Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-11-24 19:30:29| Engadget

Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets. The company's Project Zero team says it flagged the problems to ARM (which produces the GPUs) back in the summer. ARM resolved the issues on its end in July and August. However, smartphone manufacturers including Samsung, Xiaomi, Oppo and Google itself hadn't deployed patches to fix the vulnerabilities as of earlier this week, Project Zero said.Researchers identified five new issues in June and July and promptly flagged them to ARM. "One of these issues led to kernel memory corruption, one led to physical memory addresses being disclosed to userspace and the remaining three led to a physical page use-after-free condition," Project Zero's Ian Beer wrote in a blog post. "These would enable an attacker to continue to read and write physical pages after they had been returned to the system."Beer noted that it would be possible for a hacker to gain full access to a system as they'd be able to bypass the permissions model on Android and gain "broad access" to a user's data. The attacker could do so by forcing the kernel to reuse the afore-mentioned physical pages as page tables.Project Zero found that, three months after ARM fixed these issues, all of the team's test devices were still vulnerable to the flaws. As of Tuesday, the issues were not mentioned "in any downstream security bulletins" from Android manufacturers.Engadget has contacted Google, Samsung, Oppo and Xiaomi to ask when they will deploy the fixes to their Android devices and why it has taken so long for them to do so. As SamMobile notes, Samsung's Galaxy S22 series devices and the company's Snapdragon-powered handsets aren't affected by these vulnerabilities.


Category: Marketing and Advertising

 

Latest from this category

22.12Nintendo has huge discounts on Switch 2 games in its holiday sale
22.12Pirate group Anna's Archive says it has scraped Spotify in its entirety
22.12Call of Duty co-creator Vince Zampella killed in a car crash
22.12The Indie Game Awards snatches back two trophies from Clair Obscur over its use of generative AI
22.12Uber allows violent felons to drive on its platform, investigation finds
22.12Paramount has an updated Warner Bros. Discovery bid
22.12Instacart is ending its controversial price tests
22.12How to pair controllers with the Nintendo Switch 2
Marketing and Advertising »

All news

23.12Tuesday Watch
23.12An American Dream at risk: What happens to a small Nebraska town when 3,200 workers lose their jobs
23.12ETMarkets Smart Talk | Nifty at record highs, but portfolio returns lag amid market polarisation: Pawan Kumar
23.12ETFs, mutual funds or direct stocks? Choosing the right route for global investing: Nikhil Advani
23.12Ambuja Cements, Orient Cement shares zoom up to 10% following board approval for merger with Orient Cement
23.12Trump says it would be 'smart' for Venezuela's Maduro to leave power
23.12Amazon blocks 1,800 job applications from suspected North Korean agents
23.12Belrise Industries shares skyrocket 11% to new 52-week high after likely block deal
More »
Privacy policy . Copyright . Contact form .