Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

13.01Framework increases Desktop prices by up to $460 due to RAM crisis
12.01Our favorite UGreen 3-in-1 wireless charger is 32 percent off right now
12.01Lego's first Pokémon sets are now available for pre-order
12.01Anthropic made a version of its coding AI for regular people
12.01The Disney+ Hulu bundle is on sale for $10 for one month right now
12.01Mark Zuckerberg announces new 'Meta Compute' initiative for its data center and AI projects
12.01Paramount won't quit, files suit against Warner Bros. Discovery over rejected bid
12.01India is proposing another far-reaching security rule for smartphones
Marketing and Advertising »

All news

13.01Reliance Industries shares slip 2%, down 8% in 2026. Time to buy before Q3?
13.01ICICI Prudential Life Q3 Results: PAT jumps 19% YoY to Rs 397 crore, net premium income drops 4%
13.01The biggest client red flags solopreneurs face
13.01Ashish Kacholia-backed Balu Forge shares bounce back 13% after sharp YTD fall
13.01Charity shortlisted after helping keep homes warm
13.01'I volunteer at the baby bank that helped me'
13.01This is why Elon Musk thinks you shouldnt save for retirement
13.01IFCI shares surge 21% in two days amid heavy trading volumes
More »
Privacy policy . Copyright . Contact form .