Google behebt Android-Kernel-Zero-Day, der bei gezielten Angriffen ausgenutzt wurde

Teilen:

Android security updates this month patch 46 vulnerabilities, including a high-severity remote code execution (RCE) exploited in targeted attacks.

The zero-day, tracked as CVE-2024-36971, is a use after free (UAF) weakness in the Linux kernel’s network route management. It requires System execution privileges for successful exploitation and allows altering the behavior of certain network connections.

Google says that “there are indications that CVE-2024-36971 may be under limited, targeted exploitation,” with threat actors likely exploiting to gain arbitrary code execution without user interaction on unpatched devices.

Clément Lecigne, a security researcher from Google’s Threat Analysis Group (TAG), was tagged as the one who discovered and reported this zero-day vulnerability.

Even though Google has yet to provide details about how the flaw is being exploited and what threat actor is behind the attacks, Google TAG security researchers frequently identify and disclose zero-days used in state-sponsored surveillance software attacks to target high-profile individuals.

“Source code patches for these issues will be released to the Android Open Source Project (AOSP) repository in the next 48 hours,” explains the advisory.

Earlier this year, Google patched another zero-day exploited in attacks: a high-severity elevation of privilege (EoP) flaw in the Pixel firmware, tracked as CVE-2024-32896 by Google and CVE-2024-29748 by GrapheneOS (which found and reported the flaw).

Forensic companies exploited this vulnerability to unlock Android devices without a PIN and gain access to the stored data.

Google has released two patch sets for the August security updates, the 2024-08-01 and 2024-08-05 security patch levels. The latter includes all the security fixes from the first set and additional patches for third-party closed-source and Kernel components, like a critical vulnerability (CVE-2024-23350) in a Qualcomm closed-source component.

Notably, not all Android devices might need security vulnerabilities that apply to the 2024-08-05 patch level. Device vendors may also prioritize deploying the initial patch level to streamline the update process. However, this does not necessarily indicate an increased risk of potential exploitation.

It’s important to note that while Google Pixel devices receive monthly security updates immediately after release, other manufacturers may require some time before rolling out the patches. The delay is necessary for additional testing of the security patches to ensure compatibility with various hardware configurations.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:14 am, Jan. 22, 2025
Wetter-Symbol 3°C
L: 2° | H: 4°
mist
Luftfeuchtigkeit: 91 %
Druck: 1008 mb
Wind: 2 mph
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 5 km
Sonnenaufgang: 7:52 am
Sonnenuntergang: 4:31 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
2° | 4°°C 1 mm 100% 5 mph 95 % 1008 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
2° | 8°°C 1 mm 100% 17 mph 94 % 1005 mb 0 mm/h
Fr. Jan. 24 9:00 pm
Wetter-Symbol
6° | 10°°C 1 mm 100% 24 mph 91 % 1004 mb 0 mm/h
Sa. Jan. 25 9:00 pm
Wetter-Symbol
4° | 6°°C 0.89 mm 89% 8 mph 86 % 1012 mb 0 mm/h
So. Jan. 26 9:00 pm
Wetter-Symbol
5° | 8°°C 0.2 mm 20% 14 mph 86 % 1011 mb 0 mm/h
Today 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 92 % 1008 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 3°°C 0.8 mm 80% 3 mph 95 % 1006 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
4° | 4°°C 1 mm 100% 3 mph 95 % 1004 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
4° | 4°°C 0.8 mm 80% 4 mph 91 % 1003 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 5 mph 89 % 1002 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 87 % 1003 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 95 % 1004 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 3 mph 94 % 1004 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€101,666.87
4.38%
Ethereum(ETH)
€3,218.75
3.63%
XRP(XRP)
€3.07
1.10%
Fesseln(USDT)
€0.96
0.13%
Solana(SOL)
€242.63
6.43%
Dogecoin(DOGE)
€0.356671
7.44%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000020
4.03%
Pepe(PEPE)
€0.000015
3.75%
Peanut das Eichhörnchen(PNUT)
€0.364163
1.01%
Nach oben scrollen