Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

09.01Lumus brought a massively wider FOV to smartglasses at CES 2026
08.01Handwriting is my new favorite way to text with the Meta Ray-Ban Display glasses
08.01IXIs autofocusing lenses are almost ready to replace multifocal glasses
08.01Razer put a waifu in a bottle at CES 2026
08.01YouTube will let you exclude Shorts from search results
08.01Hands-on with Fender Audio's headphones and speakers at CES 2026
08.01Emerson Smart brings offline voice control to lamps and fans
08.01Engadget's best of CES 2026: All the new tech that caught our eye in Las Vegas
Marketing and Advertising »

All news

09.01Friday Watch
09.01US market breadth signals underlying strength amid global uncertainty: Arvind Sanger
09.01BHEL shares rally 5% after hitting lower circuit on China concerns. Should you buy, sell or hold?
09.01China factor explained: Jefferies and JM Financial analysts decode the upside and risks for BHEL shares after 10% crash
09.01Iran protests: Who is exiled crown prince Reza Pahlavi, son of last Shah, ousted in 1979 by Khomeini, now drawing huge support
09.01Midcap multibagger stock tumbles 13% as Q3 net profit drops 33% to Rs 72 crore
09.01Iran Protests: From 1979 Islamic Revolution to the current rial crisis, a look at Irans long history of street protests
09.01Bansal Wire shares decline 5% as 20% equity becomes eligible for trading after lock-in expiry
More »
Privacy policy . Copyright . Contact form .