Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

30.01Apple just reported its best-ever quarter for iPhone sales
30.01Using underground robots, Goods will have groceries ready for pickup in 2 minutes
29.01Amazon discovered a 'high volume' of CSAM in its AI training data but isn't saying where it came from
29.01Elon Musks SpaceX and xAI are reportedly holding merger talks
29.01Publishers are blocking the Internet Archive for fear AI scrapers can use it as a workaround
29.01Waymo begins service at San Francisco International Airport
29.01Apple acquires Q.ai for a reported $2 billion
29.01Music publishers sue Anthropic for $3 billion over flagrant piracy
Marketing and Advertising »

All news

30.01Trump threatens tariffs on countries selling oil to Cuba
30.01Venezuelan MPs approve bill to open up oil sector to private firms
30.01US stock futures fall on Apple warning, gold up
30.01Foreign inflows must to put rupee on strong footing
30.01Responders recall a mission of recovery and grief a year after the midair collision near Washington DC
30.01BofA CEO Brian Moynihan flags India as major growth engine, calls for more capital to fuel expansion
30.01Visit the North Sea oil field used to store greenhouse gas
30.01Why the US dollar hit a four-year low and could fall further
More »
Privacy policy . Copyright . Contact form .