Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

14.02Relooted, Reanimal and other new indie games worth checking out
13.02Bitcoin biopic starring Casey Affleck to use AI to generate locations and tweak performances
13.02Valve's latest Steam beta lets you add your PC's specs to game reviews
13.02Nintendos Virtual Boy accessory lets you play VR Mario and Zelda on Switch 2
13.02Good Luck, Have Fun, Don't Die rails against AI in style
13.02AI Update, February 13, 2026: AI News and Views From the Past Week
13.02Meta is reportedly working to bring facial recognition to its smart glasses
13.02The ridiculously tiny Kodak Charmera captured our hearts (and lots of shoddy pictures)
Marketing and Advertising »

All news

14.02Dalal Street Week Ahead: Protect gains, avoid fresh longs until key levels hold
14.02Relooted, Reanimal and other new indie games worth checking out
14.02Bangladeshs interests come first, says BNP chairman and PM-designate Tarique Rahman
14.02Love is in the air in Lincoln Square: Couples share how they met in the neighborhood this Valentines Day
14.02Anupam Rasayan Q3 net profit rises 12% on higher revenue
14.02Homebuilder lot supply jumps so fast that 2 housing markets are now significantly oversupplied
14.02The hidden costs of becoming an expat
14.02F&O Talk | Nifty breaches 20 & 100-DMA amid 11% VIX spike; Sudeep Shah on Coforge, 5 other top weekly movers
More »
Privacy policy . Copyright . Contact form .