Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

30.12LG to unveil a canvas-style TV at CES 2026
29.12NASA finally has a leader, but its future is no more certain
29.12How to watch the LG CES 2026 press conference
29.12Co-founder of CD Projekt Michał Kiciński has acquired GOG, the company's game storefront
29.121Password deal: Get 50 percent off plans for the holiday season
29.12Samsung plans to integrate Google Photos into its TVs
29.12How to watch the Sony Afeela CES 2026 press conference
28.12Apple escalates its appeal of a $2 billion fine from a UK antitrust lawsuit
Marketing and Advertising »

All news

30.12Tuesday Watch
30.12Gujarat Kidney shares list at 6% premium over IPO price
30.12Swedish workers trial 'friendship hour' to combat loneliness
30.12Sensex falls over 200 pts, Nifty below 25,900 as foreign flow woes linger
30.12ETMarkets Smart Talk| India is entering the early stages of an earnings-upgrade cycle: Edelweiss MFs Trideep Bhattacharya
30.12ETMarkets Smart Talk | From liquidity to earnings: Why 2026 will be a stock-pickers market, Nikhil Khandelwal decodes
30.12Kotak Mahindra Bank fixes January 14 as record date for upcoming stock split
30.12China AI rules aim to protect children and tackle suicide risks
More »
Privacy policy . Copyright . Contact form .