android-hacking

Google Releases Android Patch Update for 3 Actively Exploited Vulnerabilities

Share:

Google has released its monthly security updates for the Android operating system, addressing 46 new software vulnerabilities. Among these, three vulnerabilities have been identified as actively exploited in targeted attacks.

One of the vulnerabilities tracked as CVE-2023-26083 is a memory leak flaw affecting the Arm Mali GPU driver for Bifrost, Avalon, and Valhall chips. This particular vulnerability was exploited in a previous attack that enabled spyware infiltration on Samsung devices in December 2022.

This vulnerability was regarded as serious enough to prompt the Cybersecurity and Infrastructure Security Agency (CISA) to issue a patching order for federal agencies in April 2023.

Another significant vulnerability, identified as CVE-2021-29256, is a high-severity issue that affects specific versions of the Bifrost and Midgard Arm Mali GPU kernel drivers. This flaw permits an unprivileged user to gain unauthorized access to sensitive data and escalate privileges to the root level.

 

 

The third exploited vulnerability, CVE-2023-2136, is a critical-severity bug discovered in Skia, Google’s open-source multi-platform 2D graphics library. It was initially disclosed as a zero-day vulnerability in the Chrome browser and allows a remote attacker who has taken over the renderer process to perform a sandbox escape and implement remote code on Android devices.

Besides these, Google’s July Android security bulletin highlights another critical vulnerability, CVE-2023-21250, affecting the Android System component. This issue can cause remote code execution without user interaction or additional execution privileges, making it particularly precarious.

These security updates are rolled out in two patch levels. The initial patch level, made available on July 1, focuses on core Android components, addressing 22 security defects in the Framework and System components.

The second patch level, released on July 5, targets kernel and closed source components, tackling 20 vulnerabilities in Kernel, Arm, Imagination Technologies, MediaTek, and Qualcomm components.

It’s important to note that the impact of the addressed vulnerabilities may extend beyond the supported Android versions (11, 12, and 13), potentially affecting older OS versions no longer receive official support.

Google has further launched particular security patches for its Pixel devices, dealing with 14 vulnerabilities in Kernel, Pixel, and Qualcomm components. Two of these critical weaknesses could result in privilege elevation and denial-of-service attacks.

 

(c) Swati Khandelwal

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:56 pm, Apr 3, 2025
weather icon 12°C
L: 11° | H: 13°
broken clouds
Humidity: 73 %
Pressure: 1020 mb
Wind: 5 mph ENE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 83%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 6:30 am
Sunset: 7:36 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
11° | 13°°C 0 mm 0% 13 mph 85 % 1020 mb 0 mm/h
Sat Apr 05 10:00 pm
weather icon
7° | 17°°C 0 mm 0% 13 mph 72 % 1022 mb 0 mm/h
Sun Apr 06 10:00 pm
weather icon
7° | 13°°C 0 mm 0% 13 mph 79 % 1026 mb 0 mm/h
Mon Apr 07 10:00 pm
weather icon
6° | 14°°C 0 mm 0% 9 mph 75 % 1029 mb 0 mm/h
Tue Apr 08 10:00 pm
weather icon
6° | 16°°C 0 mm 0% 8 mph 71 % 1029 mb 0 mm/h
Tomorrow 1:00 am
weather icon
11° | 12°°C 0 mm 0% 3 mph 74 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 11°°C 0 mm 0% 4 mph 79 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
10° | 10°°C 0 mm 0% 5 mph 85 % 1020 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0 mm 0% 10 mph 64 % 1020 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
20° | 20°°C 0 mm 0% 12 mph 40 % 1019 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
18° | 18°°C 0 mm 0% 13 mph 38 % 1018 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
15° | 15°°C 0 mm 0% 11 mph 54 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
12° | 12°°C 0 mm 0% 10 mph 64 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€74,649.26
-2.27%
Ethereum(ETH)
€1,629.55
-3.38%
Tether(USDT)
€0.90
-0.03%
XRP(XRP)
€1.85
-2.07%
USDC(USDC)
€0.90
-0.01%
Solana(SOL)
€105.33
-7.03%
Dogecoin(DOGE)
€0.144451
-5.76%
Shiba Inu(SHIB)
€0.000011
-2.15%
Pepe(PEPE)
€0.000006
-9.26%