Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

07.02The Crypto.com guy bought AI.com (and a Super Bowl ad)
06.02Apple will reportedly allow third-party AI assistants in CarPlay
06.02Disney+ loses access to Dolby Vision in some European countries
06.02The new trailer for The Super Mario Galaxy Movie shows Yoshi absolutely devouring a Magikoopa
06.02Noble Audio has released a USB-C Bluetooth dongle for high fidelity transmission
06.02Spotify now lets you swipe on songs to learn more about them
06.02Get a four-pack of first-gen AirTags for only $64
06.02NASA will now allow astronauts to take their smartphones to space
Marketing and Advertising »

All news

07.02Evening Headlines
07.02Where does the capex focus lie in Union Budget 2026?
07.02ETMarkets Smart Talk | Why the Budgets 4.3% fiscal deficit target is a positive for markets: Sunil Sanghai
07.02Quant Small Cap Fund exits ONGC and 3 others, adds Gillette India in its portfolio in January
07.02Bullions biggest selloff: How macro shocks triggered a healthy correction in gold, silver
07.02IPO calendar: 3 issues worth Rs 3,871 crore hit the market next week as Fractal, Aye Finance hit markets
07.02Markets eye brighter side: Sensex, Nifty recover from early losses amid IT rout
07.02Feb 6, Business Letter Templates (Free Samples You Can Copy + Use)
More »
Privacy policy . Copyright . Contact form .