Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

24.04Senate passes bill that could ban TikTok
24.04Frida Uncensored shoots explicitly instructional videos for new and expecting moms
23.04The world's leading AI companies pledge to protect the safety of children online
23.04Tesla previews ride-hailing experience ahead of August robotaxi unveil
23.04Rolands mobile podcasting studio gives you a mic and streaming app for $140
23.04Ray-Ban Meta smart glasses do the AI thing without a projector or subscription
23.04Samsung's Galaxy S24 Ultra is on sale for its lowest price yet at Amazon and Best Buy
23.04Amazons updated grocery delivery program has some strings attached
Marketing and Advertising »

All news

24.04Mongolia: Legal Alert: Regulation Of Public-Private Partnership - GRATA International
24.04United States: Ohio Department Of Taxation Begins To Issue Findings That Implement Recent Exempt Facility Legislation - Vorys Sater Seymour & Pease
24.04 Piero Cipollone: Innovation, integration and independence: taking the Single Euro Payments Area to the next level
24.04Canada: Federal Government Releases Proposals To Increase The Capital Gains Inclusion Rate And Other Tax Measures Relevant To Employers - McCarthy Tétrault LLP
24.04Canada: Federal Government Releases Proposals Related To Mutual Fund Corporations, Synthetic Equity Arrangements, And Qualified Investments For Registered Plans - McCarthy Tétrault LLP
24.04Canada: Federal Government Releases Proposals Relating To Clean Electricity Investment Tax Credit, Clean Technology Manufacturing Investment Tax Credit, And New Electric Vehicle Supply Chain Investment Tax Credit - McCarthy Tétrault LLP
24.04Lloyds profits drop 28% after bumper 2023
24.04Germany: Berufsweg Teleärztin - Luther S.A.
More »
Privacy policy . Copyright . Contact form .