ZeroHour
CyberScooppublished ()ingested @gregotto

Android patches several vulnerabilities in first security update of 2025

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20154
In Modem, there is a possible out of bounds write due to a missing bounds check.

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00720348; Issue ID: MSV-2392.

NVD description · AI analysis pending
8.84%
  • mediatek lr12a
  • mediatek lr13
  • mediatek nr16.r1.mp
  • +1 more
CVE-2024-21464
Memory corruption while processing IPA statistics, when there are no active clients registered.

Memory corruption while processing IPA statistics, when there are no active clients registered.

NVD description · AI analysis pending
7.8<1%
  • qualcomm fastconnect 6700 firmware
  • qualcomm fastconnect 6900 firmware
  • qualcomm fastconnect 7800 firmware
  • +1 more
CVE-2024-49747
+4 in the same advisory: …49748 …43770 …43771 …43096
In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code.

In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD description · AI analysis pending
9.8
group max
<1%
  • google android
Full article533 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The bulletin identifies five critical remote code execution (RCE) vulnerabilities affecting the core components of Android’s system.

Listen to this article

0:00

Learn more.

(GABRIEL BOUYS/AFP via Getty Images)

Android has released its first security update of the year, disclosing several critical and high-severity vulnerabilities that affect a wide range of Android devices. 

The bulletin identifies five critical remote code execution (RCE) vulnerabilities affecting what Android categorizes as the “system,” which encompasses Android’s core components and underlying architecture. These vulnerabilities could allow attackers to execute code without needing additional privileges. Devices receiving a security patch level dated January 5, 2025, or later are protected from these vulnerabilities.

The vulnerabilities are cataloged as follows: 

  • CVE-2024-43096
  • CVE-2024-43770 
  • CVE-2024-43771
  • CVE-2024-49747 
  • CVE-2024-49748

Samsung, which uses Android as the operating system on its devices, pushed a patch for these vulnerabilities in a December update. 

The vulnerabilities were discovered by researchers at Oppo’s Amber Security Lab. Oppo is a Chinese consumer electronics manufacturer that runs a custom version of Android OS on its devices. 

Additionally, the bulletin gives details on vulnerabilities in components from third-party vendors, including MediaTek and Qualcomm. 

A component vulnerability in MediaTek’s modem chipset (CVE-2024-20154) can allow data to be written to the wrong place because there’s no check to make sure it stays within safe limits. This problem might allow someone to control the device from afar by tricking it into connecting to a fake cell tower. 

One particular Qualcomm vulnerability, cataloged as CVE-2024-21464, arises from a problem in the part of a device that manages data networks and connections. There is an issue when data is being copied without checking if it fits properly into the memory space. This can cause errors in the memory, especially when no active users are connected to the device’s internet capabilities.

Consumers with Google-issued devices, such as the Google Pixel, or Android partners are asked to use these patches promptly and efficiently.

You can read the full bulletin here

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-january-2025/