Uhale Android-based photo frames deliver malware on boot
Summary
Hide ▲
Show ▼
Uhale Android-based digital picture frames have been found to download and execute malware on boot due to multiple critical security vulnerabilities. The issues were reported to the manufacturer, ZEASN (now Whale TV), but went unaddressed. The malware is linked to the Mezmess and Voi1d families. The devices also have multiple security gaps, including disabled SELinux, rooted systems, and use of AOSP test-keys. The vulnerabilities allow for remote code execution, command injection, and unauthorized file access. The exact number of affected users is unknown due to the devices being sold under various brands.
Timeline
-
13.11.2025 15:00 1 articles · 23h ago
Uhale photo frames download malware on boot
Uhale Android-based digital picture frames have been found to download and execute malware on boot due to multiple critical security vulnerabilities. The issues were reported to the manufacturer, ZEASN (now Whale TV), but went unaddressed. The malware is linked to the Mezmess and Voi1d families. The devices also have multiple security gaps, including disabled SELinux, rooted systems, and use of AOSP test-keys. The vulnerabilities allow for remote code execution, command injection, and unauthorized file access. The exact number of affected users is unknown due to the devices being sold under various brands.
Show sources
- Popular Android-based photo frames download malware on boot — www.bleepingcomputer.com — 13.11.2025 15:00
Information Snippets
-
Uhale photo frames download malicious payloads from China-based servers at boot.
First reported: 13.11.2025 15:001 source, 1 articleShow sources
- Popular Android-based photo frames download malware on boot — www.bleepingcomputer.com — 13.11.2025 15:00
-
The malware is linked to the Mezmess and Voi1d botnet families.
First reported: 13.11.2025 15:001 source, 1 articleShow sources
- Popular Android-based photo frames download malware on boot — www.bleepingcomputer.com — 13.11.2025 15:00
-
The devices have SELinux disabled, are rooted by default, and use AOSP test-keys.
First reported: 13.11.2025 15:001 source, 1 articleShow sources
- Popular Android-based photo frames download malware on boot — www.bleepingcomputer.com — 13.11.2025 15:00
-
Multiple vulnerabilities, including CVE-2025-58392, CVE-2025-58397, CVE-2025-58388, CVE-2025-58394, CVE-2025-58396, and CVE-2025-58390, were discovered.
First reported: 13.11.2025 15:001 source, 1 articleShow sources
- Popular Android-based photo frames download malware on boot — www.bleepingcomputer.com — 13.11.2025 15:00
-
The Uhale app has over 500,000 downloads on Google Play and 11,000 reviews in the App Store.
First reported: 13.11.2025 15:001 source, 1 articleShow sources
- Popular Android-based photo frames download malware on boot — www.bleepingcomputer.com — 13.11.2025 15:00