ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Android security update contains 2 actively exploited vulnerabilities

criticalVulnerability exploited in the wildimportance 60CVE-2024-43093CVE-2024-50302

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-43093
Local Privilege Escalation via Unicode Path Filter Bypass in Android Framework

CVE-2024-43093 is a privilege escalation flaw in the Android Framework's ExternalStorageProvider (the component behind the system document/file picker), where the shouldHideDocument function mishandles Unicode normalization, allowing crafted file paths to bypass the filter that hides sensitive directories such as app-private storage (CWE-176). It is triggered locally: an app with no additional execution privileges can exploit it with user interaction, for example when a user selects a file or location through the documents UI. A successful bypass grants unauthorized access to otherwise protected directories and can lead to local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.3, vector AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Any device running the Android Framework is in scope, meaning effectively the entire Android installed base, although the local access and user-interaction requirements limit practical exploitability to targeted scenarios. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-07 and Google has indicated it may be under limited, targeted exploitation; no public proof-of-concept is known, and EPSS currently rates the 30-day exploitation probability at a modest 0.7%, though the KEV listing is the authoritative in-the-wild signal.

Do: Apply Google's Android security updates immediately — the fix is included in the November 2024 Android Security Bulletin (security patch level 2024-11-01) or later — and verify the device's security patch level in Settings; OEM devices (e.g., Samsung) may receive the fix through vendor updates on a lag. Per the CISA KEV required action, treat patching as urgent or apply vendor mitigations, and as an interim measure restrict sideloaded/untrusted app installs and caution users when picking files through the document picker. Ransomware linkage is unknown, and the user-interaction requirement means exploitation is targeted rather than wormable.

7.3<1% KEV
  • Google Android (Android Framework component)
massbillions of Android devices worldwide (Android runs on roughly 70% of global smartphones)
CVE-2024-50302
Kernel Memory Leak via Uninitialized HID Report Buffer in Linux Kernel

CVE-2024-50302 is a use of uninitialized resource flaw (CWE-908) in the Linux kernel's HID (Human Interface Device) core, where the shared report buffer was not zero-initialized at allocation. An attacker can trigger it by getting the kernel to process a specially crafted HID report, causing uninitialized kernel memory to be exposed to the requesting driver. The impact is an information disclosure: a local attacker, or a malicious/malfunctioning HID device, could leak kernel memory contents, which could in turn aid further attacks. Because nearly all Linux-based systems compile in HID support, affected code is present in Linux distributions, Android, and Siemens industrial products (SIMATIC S7-1500 TM MFP firmware and SINEC OS). The vulnerability is being actively exploited: CISA added it to the KEV catalog on 2025-03-04, and it is among the actively exploited flaws addressed in Google's March 2025 Android security update.

Do: Apply the fixes per vendor channels: install the March 2025 Android security update on Android devices (it is listed as actively exploited and is in CISA KEV, required under BOD 22-01 for federal agencies), and apply Debian kernel updates and Siemens (SIMATIC S7-1500 TM MFP firmware / SINEC OS) updates once issued. Operators should inventory systems running Linux kernels with the HID core (most systems) and prioritize patching, since a local attacker or malicious USB HID device can leak kernel memory; the fix zero-initializes the HID report buffer and is included in current stable kernel branches.

5.5<1% KEV
  • Linux kernel (HID core)
  • Google Android
  • Debian Linux
  • +2 more
massBillions of devices ship affected Linux kernel HID code (Linux runs on ~3+ billion Android devices plus millions of servers, desktops, and industrial systems),…
Full article283 words · extracted from cyberscoop.com · click to collapse

Google’s monthly batch of security fixes addressed 43 vulnerabilities.

Listen to this article

0:00

Learn more.

(GABRIEL BOUYS/AFP via Getty Images)

Google addressed 43 vulnerabilities affecting Android devices in its March security update, including a pair of software defects reportedly under active exploitation. Google said the two vulnerabilities — CVE-2024-43093 and CVE-2024-50302 — “may be under limited, targeted exploitation.”

The most severe of the flaws under active exploitation, CVE-2024-43093, carries a CVSS score of 7.8 and was added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog in November. The Android framework privilege escalation vulnerability allows attackers to gain local escalation of privilege without additional execution privileges, but requires user interaction for exploitation. 

Google’s security advisory includes 11 high-severity flaws and 10 critical-severity vulnerabilities affecting the Android system, the most severe of which could lead to remote code execution. Google also addressed nine high-severity vulnerabilities affecting the Android framework. 

Google’s Android security update contains two patch levels — 2025-03-01 and 2025-03-05 — allowing Android partners to easily fix certain common vulnerabilities on different devices. The second patch includes fixes for a trio of high-severity flaws affecting the kernel, a pair of vulnerabilities in MediaTek components and a total of eight high-severity defects in Qualcomm components. 

Pixel device users will get access to the latest Android security updates shortly, yet other Android manufacturers typically release security patches at a slower pace after they’ve customized operating system updates specific to their devices. 

Google said source code patches for the flaws were released to the Android Open Source Project repository. The company routinely encourages all Android partners to fix all issues in its monthly security bulletins, following the most recent security patch level.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-march-2025/