Security News > 2021 > February > Google Patches Over a Dozen High-Severity Privilege Escalation Flaws in Android

Google Patches Over a Dozen High-Severity Privilege Escalation Flaws in Android
2021-02-03 04:38

Google this week published its Android security bulletin for February 2021, which includes information on more than 40 vulnerabilities, most of which could lead to elevation of privilege.

Tracked as CVE-2021-0325, the issue is considered critical on Android 8.1 and 9 platform releases, but has only a high severity rating on Android 10 and 11, Google's advisory explains.

Two other flaws patched in Media Framework this month, namely CVE-2021-0332 and CVE-2021-0335, were rated high severity.

Google also patched an information disclosure flaw in Android runtime, along with nine elevation of privilege and one denial of service issue in Framework, all of which were rated high severity.

The System component received patches for six vulnerabilities, namely one critical remote code execution bug and five high-severity elevation of privilege issues.

Pixel devices, Google explains, will receive patches for all the security vulnerabilities in the February 2021 Android security bulletin, and for the bug described in the Pixel update bulletin.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/Qhie1GwT91I/google-patches-16-high-severity-privilege-escalation-vulnerabilities-android

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-02-10 CVE-2021-0325 Out-of-bounds Write vulnerability in Google Android
In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow.
network
low complexity
google CWE-787
8.8
2021-02-10 CVE-2021-0332 Use After Free vulnerability in Google Android 10.0/11.0
In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2021-02-10 CVE-2021-0335 Use After Free vulnerability in Google Android 11.0
In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free.
network
low complexity
google CWE-416
6.5

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 102 253 4225 4525 728 9731