ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Zero-Day Alert: Latest Android Patch Update Includes Fix for Newly Actively Exploited Flaw

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-35674

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-35674
Local Privilege Escalation in Android Framework (CVE-2023-35674)

CVE-2023-35674 is a privilege escalation flaw in the Android Framework caused by a logic error in the onCreate function of WindowState.java, which allows a background activity to be launched incorrectly. It is triggered by code already running on the device: an app with no special permissions can exploit the logic error, and no user interaction is required for exploitation. A successful attacker gains local escalation of privilege with high impact on the confidentiality, integrity, and availability of the affected device. Any Android device running an unpatched Android Framework build is in scope, and Google addressed the flaw in a monthly Android security update. The vulnerability was actively exploited as a zero-day and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-13; no public proof-of-concept is known.

Do: Apply the latest monthly Android security update delivered by Google or the device OEM as soon as it is available, and verify each device's Android security patch level reflects the fixed release; no workaround is documented in the available data. As an entry on the CISA KEV catalog, federal and critical-infrastructure organizations are required to apply the vendor fix or discontinue use per the KEV required action. Since exploitation requires code already running locally on the device, prioritize patching devices that install untrusted or third-party apps.

7.83% KEV
  • Google Android (Android Framework)
massbillions of devices (Android runs on roughly 3 billion+ active devices worldwide)
Full article246 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananSep 06, 2023Zero Day / Mobile Security

Google has rolled out monthly security patches for Android to address a number of flaws, including a zero-day bug that it said may have been exploited in the wild.

Tracked as CVE-2023-35674, the high-severity vulnerability is described as a case of privilege escalation impacting the Android Framework.

“There are indications that CVE-2023-35674 may be under limited, targeted exploitation,” the company said in its Android Security Bulletin for September 2023 without delving into additional specifics.

The update also addresses three other privilege escalation flaws in Framework, with the search giant noting that the most severe of these issues “could lead to local escalation of privilege with no additional execution privileges needed” sans any user interaction.

Google said it has further plugged a critical security vulnerability in the System component that could lead to remote code execution without requiring interaction on the part of the victim.

“The severity assessment is based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed,” it added.

In total, Google has fixed 14 flaws in the System module and two shortcomings in the MediaProvider component, the latter of which will be delivered as a Google Play system update.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/09/zero-day-alert-latest-android-patch.html