Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

17.01How to cancel CyberGhost and get a refund
17.01Papers Please but with zombies, a farming-based shoot-'em-up and other new indie games worth checking out
16.01Google is appealing the ruling from its search antitrust case to avoid sharing data with rivals
16.01CyberGhost VPN review: Despite its flaws, the value is hard to beat
16.01Anthropic opens up its Claude Cowork feature to anyone with a $20 subscription
16.01OpenAI is bringing ads to ChatGPT
16.01The mother of one of Elon Musk's children is suing xAI over nonconsensual deepfake images
16.01Lego's latest educational kit seeks to teach AI as part of computer science, not to build a chatbot
Marketing and Advertising »

All news

17.01How to cancel CyberGhost and get a refund
17.01Papers Please but with zombies, a farming-based shoot-'em-up and other new indie games worth checking out
17.01SIP stocks! HDFC Securities names 10 companies to accumulate in 2026. Check details
17.01Rs 2.5 lakh crore IPO boom in 2026 could create liquidity drain, says HDFC Securities; pegs Nifty at 28,720
17.01FIIs dump Rs 22,530 crore worth of domestic shares in first fortnight of January
17.01Elmhurst museum explores history of healthcare in DuPage County in new exhibit
17.01Nifty consolidates below 25,900 as markets await decisive trigger
17.01Gold-to-silver ratio hits 13-year low as silvers 170% surge leaves gold behind. What should investors do?
More »
Privacy policy . Copyright . Contact form .