ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Android July 2019 Security Update Patches 33 New Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-2104
In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields.

In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-131356202

NVD description · AI analysis pending
5.5<1%
  • google android
CVE-2019-2276
+1 in the same advisory: …2278
Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Aut

Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24

NVD description · AI analysis pending
9.8
group max
<1%
  • qualcomm mdm9607 firmware
  • qualcomm msm8996au firmware
  • qualcomm qca6174a firmware
  • +1 more
CVE-2019-2307
+3 in the same advisory: …2305 …2328 …2326
Possible integer underflow due to lack of validation before calculation of data length in 802.11 Rx management configuration in Snapdragon Auto, Snapdragon Cons

Possible integer underflow due to lack of validation before calculation of data length in 802.11 Rx management configuration in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX20, SDX24

NVD description · AI analysis pending
9.8
group max
2%
  • qualcomm mdm9150 firmware
  • qualcomm mdm9206 firmware
  • qualcomm mdm9607 firmware
  • +1 more
Full article373 words · extracted from thehackernews.com · click to collapse

Swati KhandelwalJul 02, 2019

Google has started rolling out this month's security updates for its mobile operating system platform to address a total of 33 new security vulnerabilities affecting Android devices, 9 of which have been rated critical in severity.

The vulnerabilities affect various Android components, including the Android operating system, framework, library, media framework, as well as Qualcomm components, including closed-source components.

Three of the critical vulnerabilities patched this month reside in Android's Media framework, the most severe of which could allow a remote attacker to execute arbitrary code on a targeted device, within the context of a privileged process, by convincing users into opening a specially crafted malicious file.

"The severity assessment is based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed," the company says.

Out of the remaining seven critical vulnerabilities, one affects Android Library, one affects the System, two resides in Qualcomm components (one in DSP_Services and one in Kernel), and three resides in Qualcomm closed-source components.

Besides this, a high-severity flaw (CVE-2019-2104) in the Android Framework could allow an installed malicious app to bypass user interaction requirements in an attempt to gain access to additional permissions.

Six high-severity vulnerabilities addressed in Qualcomm components resides in WLAN Host (CVE-2019-2276, CVE-2019-2307), WLAN Driver (CVE-2019-2305), HLOS (CVE-2019-2278), and Audio (CVE-2019-2326, CVE-2019-2328).

According to the Android security advisory, none of the flaws addressed this month were publicly disclosed or found being exploited in the wild.

Apart from releasing patches for security vulnerabilities, the Android Security Patch for July 2019 also includes fixes for various issues in some of the supported version of Pixel devices.

Pixel smartphone users will get the July updates shortly, while others will have to wait for their Android device manufacturers or service providers to roll out the security patches for their devices.

Users are strongly recommended to download the most recent Android security updates as soon as they are available in order to keep their Android devices protected against any potential attack.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/07/android-security-update.html