Mobile batteries become prime target for hackers
The juice packs could broadcast information about their users that even the hard drive can't
Batteries have become a new security risk for smartphone users, with a group of security researchers saying they are able to transmit personal data to hackers.
Lukasz Olejnik, Gunes Acar, Claude Castelluccia and Claudia Diaz have written a paper outlining the risks, saying a piece of software used in the HTML5 web language transmits data such as how much power is still left in a battery so websites using the code can save power while browsing.
However, it can also be used maliciously to track people as they navigate around the web, revealing which sites they visit and what kind of data they are inputting.
Unlike other actions carried out on a mobile, such as downloading an application, you don't have to grant HTML5 permission to pass this information onto the wider world. Therefore, a smartphone will respond to battery information requests without checking with you whether that's OK.
As a user navigates around different mobile websites, this information will be transmitted from each site using HTML, meaning intelligent hackers could learn quite a lot about the owner.
And, unlike the security measures put in place by private browsers and VPNs, this HTML5 bug will let the internet know where you've been thanks to the hole that hasn't been patched.
The researchers argued in their paper that smartphone users should be able to grant or deny permission for this data to be broadcast, leaving it down to them whether their battery power is preserved when accessing certain websites or not. They should also be given more information about the type of data transmitted by their phone's battery, the researchers said.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
AI is shrinking attack windows, and it’s forcing a complete rethink of cyber resilience – here’s how organizations can prepareNews Commvault has urged companies to improve their business continuity and resilience plans in the face of flaws spotted by AI
-
Anthropic targets vulnerability detection gains with Claude Security public beta — here's what users can expectNews The Claude Mythos developer is aiming for a more limited approach to cyber tooling for public consumption
-
Researchers warn millions of RDP and VNC servers are wide open to exploitationNews Researchers at Forescout spotted millions of RDP and VNC servers exposed online
-
Brace yourselves for a vulnerability explosion, Forescout warnsNews AI advances are helping identify software flaws at record pace and scale, but that's not the good news some would think
-
Ubuntu vulnerability exposes enterprises to root escalation, complete system compromiseNews The high-severity Ubuntu vulnerability allows an unprivileged local attacker to escalate privileges through the interaction of two standard system components
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
Millions of developers could be impacted by flaws in Visual Studio Code extensions – here's what you need to know and how to protect yourselfNews The VS Code vulnerabilities highlight broader IDE security risks, said OX Security
-
CVEs are set to top 50,000 this year, marking a record high – here’s how CISOs and security teams can prepare for a looming onslaughtNews While the CVE figures might be daunting, they won't all be relevant to your organization