Google: Android patch gap makes n-days as dangerous as zero-days

Teilen:

Google has published its annual 0-day vulnerability report, presenting in-the-wild exploitation stats from 2022 and highlighting a long-standing problem in the Android platform that elevates the value and use of disclosed flaws for extended periods.

More specifically, Google’s report highlights the problem of n-days in Android functioning as 0-days for threat actors.

The problem stems from the complexity of the Android ecosystem, involving several steps between the upstream vendor (Google) and the downstream manufacturer (phone manufacturers), significant discrepancies in security update intervals between different device models, short support periods, responsibility mixups, and others issues.

zero-day vulnerability is a software flaw known before a vendor becomes aware or fixes it, allowing it to be exploited in attacks before a patch is available. However, an n-day vulnerability is one that is publicly known with or without a patch.

For example, if a bug is known in Android before Google, it is called a zero-day. However, once Google learns about it, it becomes an n-day, with the n reflecting the number of days since it became publicly known.

Google warns that attackers can use n-days to attack unpatched devices for months, using known exploitation methods or devising their own, despite a patch already being made available by Google or another vendor.

This is caused by patch gaps, where Google or another vendor fixes a bug, but it takes months for a device manufacturer to roll it out in their own versions of Android.

“These gaps between upstream vendors and downstream manufacturers allow n-days – vulnerabilities that are publicly known – to function as 0-days because no patch is readily available to the user and their only defense is to stop using the device,” explains Google’s report.

“While these gaps exist in most upstream/downstream relationships, they are more prevalent and longer in Android.”

N-days as effective as 0-days

In 2022, many issues of this kind impacted Android, most notably CVE-2022-38181, a vulnerability in the ARM Mali GPU. This flaw was reported to the Android Security team in July 2022, deemed as “won’t fix,” patched by ARM in October 2022, and finally incorporated in the Android April 2023 security update.

This flaw was found to be exploited in the wild in November 2022, a month after ARM released a fix.

Exploitation continued unabated until April 2023, when the Android security update pushed the fix, a whopping six months after ARM addressed the security problem.

  • CVE-2022-3038: Sandbox escape flaw in Chrome 105, which was patched in June 2022, yet remained unaddressed on vendor browsers based on earlier Chrome versions, like Samsung’s ‘Internet Browser.’
  • CVE-2022-22706: Flaw in the ARM Mali GPU kernel driver patched by the vendor in January 2022.

The two flaws were found to be exploited in December 2022 as part of an attack chain that infected Samsung Android devices with spyware.

Samsung released a security update for CVE-2022-22706 in May 2023, while the Android security update adopted ARM’s fix on the June 2023 security update, recording a staggering 17-month delay.

Even after Google releases the Android security update, it takes device vendors up to three months to make the fixes available for supported models, giving attackers yet another window of exploitation opportunity for specific devices.

This patch gap effectively makes an n-day as valuable as a zero-day for threat actors who can exploit it on unpatched devices. Some may consider these n-days more useful than zero-days as the technical details have already been published, potentially with proof-of-concept (PoC) exploits, making it easier for threat actors to abuse them.

The good news is that Google’s 2022 activity summary shows that zero-day flaws are down compared to 2021, at 41 found, while the most significant drop was recorded in the browsers category, which counted 15 flaws last year (was 26 in 2021).

Another notable finding is that more than 40% of the zero-day vulnerabilities discovered in 2022 were variants of previously reported flaws, as bypassing fixes for known flaws is usually easier than finding a novel 0-day that can serve on similar attack chains.

 

(c) Lawrence Abrams

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:35 am, Mai 24, 2025
Wetter-Symbol 14°C
L: 14° | H: 15°
overcast clouds
Luftfeuchtigkeit: 90 %
Druck: 1012 mb
Wind: 9 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 8:58 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 15°°C 0.24 mm 24% 14 mph 90 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 19°°C 1 mm 100% 16 mph 92 % 1015 mb 0 mm/h
Mo. Mai 26 10:00 pm
Wetter-Symbol
10° | 16°°C 0.78 mm 78% 15 mph 78 % 1017 mb 0 mm/h
Di. Mai 27 10:00 pm
Wetter-Symbol
13° | 17°°C 1 mm 100% 15 mph 95 % 1016 mb 0 mm/h
Mi. Mai 28 10:00 pm
Wetter-Symbol
14° | 21°°C 1 mm 100% 16 mph 96 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
14° | 16°°C 0.24 mm 24% 11 mph 90 % 1012 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
16° | 20°°C 0.06 mm 6% 13 mph 82 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 14 mph 68 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 11 mph 67 % 1010 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 11 mph 84 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0.2 mm 20% 11 mph 88 % 1008 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
14° | 14°°C 1 mm 100% 16 mph 92 % 1007 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
13° | 13°°C 0.8 mm 80% 14 mph 84 % 1008 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,131.85
-2.30%
Ethereum(ETH)
€2,249.22
-4.12%
Fesseln(USDT)
€0.88
0.03%
XRP(XRP)
€2.06
-3.57%
Solana(SOL)
€154.00
-3.92%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.201007
-6.88%
Shiba Inu(SHIB)
€0.000012
-6.61%
Pepe(PEPE)
€0.000012
-9.91%
Peanut das Eichhörnchen(PNUT)
€0.309779
-5.58%
Nach oben scrollen