Google addressed an actively exploited zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-28581 | Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE. Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-35681 | In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2023-35674 | Local Privilege Escalation in Android Framework (CVE-2023-35674) CVE-2023-35674 is a privilege escalation flaw in the Android Framework caused by a logic error in the onCreate function of WindowState.java, which allows a background activity to be launched incorrectly. It is triggered by code already running on the device: an app with no special permissions can exploit the logic error, and no user interaction is required for exploitation. A successful attacker gains local escalation of privilege with high impact on the confidentiality, integrity, and availability of the affected device. Any Android device running an unpatched Android Framework build is in scope, and Google addressed the flaw in a monthly Android security update. The vulnerability was actively exploited as a zero-day and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-13; no public proof-of-concept is known. Do: Apply the latest monthly Android security update delivered by Google or the device OEM as soon as it is available, and verify each device's Android security patch level reflects the fixed release; no workaround is documented in the available data. As an entry on the CISA KEV catalog, federal and critical-infrastructure organizations are required to apply the vendor fix or discontinue use per the KEV required action. Since exploitation requires code already running locally on the device, prioritize patching devices that install untrusted or third-party apps. | 7.8 | 3% | KEV |
| massbillions of devices (Android runs on roughly 3 billion+ active devices worldwide) |
Full article206 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 06, 2023

Google released September 2023 Android security updates to address multiple flaws, including an actively exploited zero-day.
Google released September 2023 Android security updates that address tens of vulnerabilities, including a zero-day flaw tracked as CVE-2023-35674 that was actively exploited in the wild.
This high-severity vulnerability CVE-2023-35674 resides in the Framework component, a threat actor could exploit the issue to escalate privileges without requiring user interaction or additional execution privileges.
“There are indications that CVE-2023-35674 may be under limited, targeted exploitation.” reads the advisory published by Google.
The company also addressed three critical remote code execution vulnerabilities, tracked as CVE-2023-35658, CVE-2023-35673, CVE-2023-35681, in the System component.
“The most severe vulnerability in this section could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.” continues the advisory.
The IT giant also addressed another critical remote code execution vulnerability, tracked as CVE-2023-28581, that affects Qualcomm closed-source components.
In total, Google has fixed 6 flaws in the Framework module, 14 in the Kernel componet, 3 issues in the Qualcomm components, and 9 issues in the Qualcomm closed-source components.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Google)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/150440/hacking/september-2023-android-security-updates-0day.html