Security News > 2021 > May > Android Issues Patches for 4 New Zero-Day Bugs Exploited in the Wild

Android Issues Patches for 4 New Zero-Day Bugs Exploited in the Wild
2021-05-19 22:35

Google on Wednesday updated its May 2021 Android Security Bulletin to disclose that four of the security vulnerabilities that were patched earlier this month by Arm and Qualcomm may have been exploited in the wild as zero-days.

CVE-2021-1906 - A flaw concerning inadequate handling of address deregistration that could lead to new GPU address allocation failure.

CVE-2021-28663 - A vulnerability in Arm Mali GPU kernel that could permit a non-privileged user to make improper operations on GPU memory, leading to a use-after-free scenario that could be exploited to gain root privilege or disclose information.

CVE-2021-28664 - An unprivileged user can achieve read/write access to read-only memory, enabling privilege escalation or a denial-of-service condition due to memory corruption.

Earlier this March, Google revealed that a vulnerability affecting Android devices that use Qualcomm chipsets was being weaponized by adversaries to launch targeted attacks.

The other flaw is CVE-2019-2215, a vulnerability in Binder - Android's inter-process communication mechanism - that's said to have been allegedly exploited by the NSO Group as well as SideWinder threat actor to compromise a victim's device and collect user information.


News URL

http://feedproxy.google.com/~r/TheHackersNews/~3/R1aqAMX8ezM/android-issues-patches-for-4-new-zero.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-05-10 CVE-2021-28664 Out-of-bounds Write vulnerability in ARM products
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages.
network
low complexity
arm CWE-787
8.8
2021-05-10 CVE-2021-28663 Use After Free vulnerability in ARM products
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free.
network
low complexity
arm CWE-416
8.8
2021-05-07 CVE-2021-1906 Improper Handling of Exceptional Conditions vulnerability in Qualcomm products
Improper handling of address deregistration on failure can lead to new GPU address allocation failure.
local
low complexity
qualcomm CWE-755
2.1
2019-10-11 CVE-2019-2215 Use After Free vulnerability in Google Android
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.
local
low complexity
google CWE-416
4.6

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Android 4 0 17 2 0 19