Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

11.12Mewgenics, the next game from The Binding of Isaac's developer, will arrive next February on PC
10.12The NES game Jaws is getting a retro physical re-release on Switch and PS5
10.12Apple TV and Apple Music were down for some users
10.12Meta is reportedly working on a new AI model called 'Avocado' and it might not be open source
10.12Spotify's new playlist feature gives users more control over their recommendation algorithm
10.12Intel loses its latest challenge to 16-year-old EU antitrust case
10.12The world premieres and other hotness from The Game Awards 2025 Day of the Devs stream
10.12PS Plus Game Catalog additions for December include Assassin's Creed Mirage
Marketing and Advertising »

All news

11.12Thursday Watch
11.12ETMarkets Smart Talk| Indias IPO boom far from over: $20 billion pipeline seen in 2026, explains Maulik Patel
11.12Positive Breakout: These 11 stocks cross above their 200 DMAs
11.12Oil extends gains after US seizure of tanker off Venezuela
11.12Trump launches $1m 'gold card' immigration visas
11.12Pension funds can now invest in more stocks, gold, silver ETFs
11.12Silver climbs Rs 11,500 to a fresh peak on global cues
11.12The Swiss city that lets you pay for most things with bitcoin
More »
Privacy policy . Copyright . Contact form .