Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

09.01It's time for Apple to reinstate ICEBlock
09.01Amazon is apparently planning a big box store in the Chicago suburbs
09.01Monarch Money's budgeting app is 50 percent off for new users
09.01The Morning After: The best of CES 2026
09.01WhatsApp might soon be subject to stricter scrutiny under the EU's Digital Services Act
09.01ExpressVPN two-year plans are up to 78 percent off right now
09.01CES: So very big, so little sustainability tech
09.01CES 2026 proved the PC industry is hosed this year
Marketing and Advertising »

All news

10.01Mutual fund SIP stoppage ratio rises to 85% in December even as contributions hit record Rs 30,002 crore
10.01Concurrent Losers: 12 stocks decline for five consecutive sessions
10.01Swiggy, Infosys among 17 stocks in BNP Paribas' top buy ideas for 2026. Check list here
10.01Trump Medias Crypto Power Play: How DJT Stock Plans to Expose Naked Short Sellers
10.01Evening Headlines
10.01Tejas Networks Q3 Results: Cons loss widens to Rs 196 crore, revenue sinks 88% YoY
10.01Dollar set for second straight weekly gain after US jobs data
10.01D-Street sees worst week since September 2025 amid tariff fears, FPI selling
More »
Privacy policy . Copyright . Contact form .