Google addresses 2 actively exploited vulnerabilities in security update
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-53150 | Out-of-Bounds Read in Linux Kernel ALSA USB Audio Driver CVE-2024-53150 is an out-of-bounds read (CWE-125) in the Linux kernel's ALSA USB-audio driver, which fails to validate the bLength field of USB audio class (UAC2/UAC3) clock source, selector, and multiplier descriptors while traversing them. It is triggered when a device presents a malformed/bogus clock descriptor with a bLength shorter than expected, causing the kernel to read beyond the descriptor buffer; an attacker with local access (e.g., by plugging in a malicious USB audio device) could gain partial kernel memory disclosure or crash the system (CVSS 3.1: 7.1, confidentiality high, availability high). Any Linux deployment whose kernel includes the affected ALSA USB-audio clock-source handling is affected, including Debian releases shipping such kernels. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-04-09, indicating exploitation in the wild, though no public proof-of-concept is known and ransomware association is unconfirmed. Do: Apply updated kernel packages from your distribution (e.g., Debian security updates) that include the ALSA USB-audio clock descriptor validation fix, and reboot to load the patched kernel; CISA KEV requires applying vendor mitigations per BOD 22-01 timelines or discontinuing use if mitigations are unavailable. Until patched, restrict untrusted physical/hotplug access to USB ports on affected systems. Check your current kernel version and confirm with the vendor that the clock-source descriptor sanity-check patch is included. | 7.1 | 1% | KEV |
| masshundreds of millions of Linux systems potentially affected (Linux ubiquity), though only those where USB audio devices can be connected are practically… | |
| CVE-2024-53197 | Out-of-Bounds Write in Linux Kernel ALSA USB Audio Driver (CVE-2024-53197) CVE-2024-53197 is an out-of-bounds access/write (CWE-787) in the Linux kernel's USB configuration handling, tied to the ALSA usb-audio driver's handling of Creative Extigy and Mbox devices. A malicious or bogus USB device that reports a bNumConfigurations value larger than the array allocated by usb_get_configuration causes the kernel to access memory beyond the end of dev->config, for example in usb_destroy_configuration. An attacker with local access — or the ability to plug a crafted USB audio device into a target — could corrupt or disclose kernel memory, with high impact to confidentiality, integrity, and availability (CVSS 7.8, local vector), typically as privilege escalation or a kernel crash. Any Linux deployment running a kernel with the vulnerable code is affected, including Debian systems. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-04-09, indicating known exploitation in the wild, though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Update the Linux kernel to a vendor release containing the CVE-2024-53197 fix — for Debian, install the current kernel security update and reboot; other distributions ship the patched kernel in their stable updates. Because exploitation requires a malicious USB audio device, restrict use of untrusted USB peripherals on sensitive or internet-adjacent hosts. Organizations subject to CISA BOD 22-01 must remediate this KEV-listed flaw per the required actions or discontinue use where mitigations are unavailable. | 7.8 | 4% | KEV |
| massmillions of Linux installations (kernel ubiquity across desktops, servers, and Debian; practically reachable only on hosts that accept untrusted USB audio… |
Full article553 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Serbian security services exploited one of the actively exploited vulnerabilities to break into the phone of a youth activist in Serbia, according to Amnesty International.
Listen to this article
0:00
Learn more.
Google addressed 62 vulnerabilities affecting Android devices in its April security update, including a pair of actively exploited software defects that were first disclosed in December. Google said the two vulnerabilities — CVE-2024-53197 and CVE-2024-53150 — “may be under limited, targeted exploitation.”
The pair of flaws under active exploitation are high-severity and affect the Linux kernel’s USB audio driver, according to Google. The most severe of the actively exploited vulnerabilities, CVE-2024-53150, carries a CVSS score of 7.1 and allows attackers to obtain potentially sensitive data.
The second actively exploited vulnerability, CVE-2024-53197, is part of a zero-day exploit chain developed by Israel-based digital forensics company Cellebrite. Serbian security services abused a Cellebrite zero-day exploit chain in “a Cellebrite product to break into the phone of a youth activist in Serbia,” Amnesty International’s Security Lab said in a report released in February.
Google’s security advisory includes two critical and 12 high-severity flaws affecting the Android system. Google also addressed one critical and 13 high-severity vulnerabilities affecting the Android framework.
The Android security update contains two patch levels — 2025-04-01 and 2025-04-05 — allowing Android partners to address a group of 27 common vulnerabilities on different devices.
The second patch includes fixes for five vulnerabilities affecting the Linux kernel, one vulnerability in an Arm component, nine defects in Imagination Technologies components, four flaws in MediaTek components and 13 total defects in Qualcomm components.
Google Pixel users will get access to the latest Android security updates automatically. Other Android device manufacturers release security patches on a slower timeline, after they’ve customized operating system updates for their specific hardware.
Google said source code patches for all 62 vulnerabilities covered in this month’s security update will be released to the Android Open Source Project repository by Wednesday.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-april-2025/