Android patches several vulnerabilities in first security update of 2025
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-20154 | In Modem, there is a possible out of bounds write due to a missing bounds check. In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00720348; Issue ID: MSV-2392. NVD description · AI analysis pending | 8.8 | 4% |
| — | ||
| CVE-2024-21464 | Memory corruption while processing IPA statistics, when there are no active clients registered. Memory corruption while processing IPA statistics, when there are no active clients registered. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2024-49747 | In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. NVD description · AI analysis pending | 9.8 group max | <1% |
| — |
Full article533 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The bulletin identifies five critical remote code execution (RCE) vulnerabilities affecting the core components of Android’s system.
Listen to this article
0:00
Learn more.
Android has released its first security update of the year, disclosing several critical and high-severity vulnerabilities that affect a wide range of Android devices.
The bulletin identifies five critical remote code execution (RCE) vulnerabilities affecting what Android categorizes as the “system,” which encompasses Android’s core components and underlying architecture. These vulnerabilities could allow attackers to execute code without needing additional privileges. Devices receiving a security patch level dated January 5, 2025, or later are protected from these vulnerabilities.
The vulnerabilities are cataloged as follows:
- CVE-2024-43096
- CVE-2024-43770
- CVE-2024-43771
- CVE-2024-49747
- CVE-2024-49748
Samsung, which uses Android as the operating system on its devices, pushed a patch for these vulnerabilities in a December update.
The vulnerabilities were discovered by researchers at Oppo’s Amber Security Lab. Oppo is a Chinese consumer electronics manufacturer that runs a custom version of Android OS on its devices.
Additionally, the bulletin gives details on vulnerabilities in components from third-party vendors, including MediaTek and Qualcomm.
A component vulnerability in MediaTek’s modem chipset (CVE-2024-20154) can allow data to be written to the wrong place because there’s no check to make sure it stays within safe limits. This problem might allow someone to control the device from afar by tricking it into connecting to a fake cell tower.
One particular Qualcomm vulnerability, cataloged as CVE-2024-21464, arises from a problem in the part of a device that manages data networks and connections. There is an issue when data is being copied without checking if it fits properly into the memory space. This can cause errors in the memory, especially when no active users are connected to the device’s internet capabilities.
Consumers with Google-issued devices, such as the Google Pixel, or Android partners are asked to use these patches promptly and efficiently.
You can read the full bulletin here.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Jail time for Maine child in 764 marks turning point in federal law enforcement
Dogged Russia-based botnet dismantled after 23-year run
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-january-2025/