Security researcher Adam Gowdiak, who is setting up the security company Security Explorations, said he's found 14 vulnerabilities in Java 2 Micro Edition (J2ME) that could allow hackers to attack Nokia's Series 40 handsets.
The Nokia Series 40 is a proprietary platform that operates the majority of the company's midrange handsets. This means that potentially hundreds of millions of devices are at risk, Gowdiak said.
With only the phone number, an attacker could send a series of messages that could exploit the flaw by putting malicious Java applications on the handset. This could allow the hacker to make calls, access the SIM card, record conversations, and install applications on the handset without the owner's knowledge, Gowdiak said.
"This could completely wipe out any security within J2ME," Gowdiak said.
He recognized that the approach would be controversial, but he said he thinks this is the best way to fund his startup.
"I know there will be some who hate this, but I am hoping to set up a world-class security research center and the company needs funds to do that," Gowdiak said. "I am good at revealing security weaknesses, and this report represents an enormous amount of research."
He scoffs at the notion that he is blackmailing the companies as he said Sun and Nokia have been briefed on the issue. Additionally, the researcher said the vulnerability report will only be available to security firms, vendors, telecommunication companies, and government agencies.
Nokia and Sun did not comment or confirm the flaws by press time.
More Security Insights
White Papers
Webcasts
Reports
Videos
BP seeking Regional Desktop Coordinator in Houston, TX
Agilent Technologies seeking Marketing Manager in Melbourne, AU
US Civilian Research and Development seeking Web App Developer in Arlington, VA
Citrus Community College seeking Programmer Analyst II in Glendora, CA
Lowes seeking ITE Project Manager in Mooresville, NC
For more great jobs, career-related news, features and services, please visit our Career Center.
Tolly Group Findings for Symantec Endpoint Protection 11.0
Attend this webcast to learn about third-party, independent research that shows how Symantec Endpoint Protection is faster and more efficient than other vendors' solutions...
read more 
NOTE: Offer valid for U.S., U.S. possessions, & Canada only