Google fixes Android zero-day exploited in the wild in targeted attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-1048 | Use-After-Free Privilege Escalation in Android Kernel (CVE-2021-1048) CVE-2021-1048 is a use-after-free (CWE-416) in ep_loop_check_proc of eventpoll.c — the Android kernel's epoll event-notification code — that can corrupt kernel memory. A local attacker (e.g., a malicious app with no special permissions) can trigger the flaw, and no user interaction is required, yielding local escalation of privilege to kernel level. Any Android device running an unpatched Android kernel is affected. The flaw is being actively exploited: it is in CISA's Known Exploited Vulnerabilities Catalog (added 2022-05-23) and reporting indicates Google fixed it as a zero-day used in targeted attacks, with coverage tying Android kernel zero-days to Cytrox/Intellexa Predator spyware campaigns. EPSS currently puts the 30-day exploitation probability at ~1.0%, but the KEV listing and in-the-wild targeting make patching urgent. Do: Apply updates per vendor instructions (CISA KEV required action): install the latest Android security/kernel updates from Google or your device OEM — Google's advisories indicate the complete fix shipped in the February 2022 Android security bulletin (2022-02-05 patch level), following the initial January 2022 fix. Fleet administrators should verify devices' security patch levels and prioritize high-value/targeted users, since observed exploitation has been targeted (spyware-linked) rather than mass-scale. No public PoC is known and ransomware use is unknown, but defenders should hunt for signs of local privilege escalation on unpatched fleets. | 7.8 | 1% | KEV |
| mass≈3 billion Android devices worldwide (Android's global active-device installed base; unpatched share unknown) | |
| CVE-2021-1906 | GPU Address Allocation DoS in Qualcomm Snapdragon and IoT Chipsets CVE-2021-1906 is an availability flaw in the GPU component of numerous Qualcomm chipsets: improper handling of address deregistration on failure can cause subsequent new GPU address allocations to fail. A local attacker with low privileges (for example, a malicious or compromised app or process on an Android device) can trigger the failure condition, causing GPU allocation failures that can hang or crash the affected device. The CVSS vector (C:N/I:N/A:H) confirms there is no confidentiality or integrity impact, so the attacker gains denial of service rather than code execution or data theft. It affects firmware for Qualcomm APQ8009, APQ8009W, APQ8017, APQ8053, APQ8064AU, APQ8096AU, AQT1000, AR8031, AR8035, AR8151, CSRA6620, and CSRA6640 across Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, Voice & Music, and Wearables product lines. CISA added the vulnerability to the KEV catalog on 2021-11-03, and it was addressed in Android security updates alongside other Qualcomm and Arm zero-days that Google reported as being used in targeted attacks. Do: Install the November 2021 (or later) Android security bulletin and Qualcomm-supplied fixes on affected phones, tablets, and embedded devices, and obtain updated firmware from device/OEM vendors for Snapdragon-based automotive, IoT, and connectivity products. Because the flaw is only exploitable locally with low privileges, exposure requires attacker code already running on the device, so applying vendor updates and checking chipset model (APQ8009/APQ8009W/APQ8017/APQ8053/APQ8064AU/APQ8096AU/AQT1000/AR8031/AR8035/AR8151/CSRA6620/CSRA6640) to confirm applicability are the key actions. | 5.5 | <1% | KEV |
| masshundreds of millions of devices (affected Qualcomm/Snapdragon chipsets ship across mainstream Android smartphones, automotive, and embedded IoT products) | |
| CVE-2021-28663 +1 in the same advisory: …28664 | Use-After-Free Privilege Escalation in Arm Mali GPU Kernel Driver CVE-2021-28663 is a use-after-free flaw in the Arm Mali GPU kernel driver, caused by mishandled GPU memory operations in the Midgard, Bifrost, and Valhall driver families. An attacker who can run code with limited privileges on a device can trigger the flaw through GPU memory operations, gaining local privilege escalation or disclosure of sensitive information (CISA's CVSS scoring uses a network attack vector). The bug is present in Midgard drivers r4p0 through r30p0, Bifrost r0p0 through r28p0 (before r29p0), and Valhall r19p0 through r28p0 (before r29p0), which ship on Android devices using Mali GPUs. It was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and was patched as part of Android security updates after Google reported it being actively exploited in targeted attacks; a public proof of concept is available on GitHub. Do: Apply Android security updates (November 2021 patch level or later) and OEM/Arm driver updates per vendor instructions, upgrading the Bifrost and Valhall GPU kernel drivers to r29p0 or later; for Midgard, move beyond the affected r4p0-r30p0 range to the latest available driver release. Organizations managing Android fleets should check device patch levels and Mali driver versions via device management tooling and prioritize this because it is on the CISA KEV list with exploitation observed in targeted attacks. Where patching is delayed, limit exposure for low-privileged users on affected devices, as exploitation requires the ability to run code on the device. | 8.8 | 12% | KEV PoC |
| masshundreds of millions of Android devices with Mali GPUs (Midgard/Bifrost/Valhall), plus any other systems running affected Mali driver versions |
Full article242 words · extracted from therecord.media · click to collapse
Google has released on Monday its monthly Android security bulletin, and the company's engineers said they patched a zero-day vulnerability that was being exploited in the wild in what they described as "limited, targeted exploitation." Tracked as CVE-2021-1048, Google said the vulnerability resided in one of the Android kernel components and was abused to elevate an attacker's privileges. Details about the attacks, the threat actor(s) behind them, and the victims have not been shared, as is the standard practice for most security patches. This approach is used in order to give end-users more time to update their vulnerable devices before the same bug is weaponized by other threat actors. CVE-2021-1048 marks the sixth Android zero-day vulnerability that was exploited this year. Google patched similar zero-days in the January and May Android security bulletins as well. The previous zero-days didn't impact the Android OS kernel itself but rather add-on components from Qualcomm and Arm, respectively. While six vulnerabilities were exploited in Android devices before patches were available (hence the zero-day categorization), Apple has had a harder time this year and the company patched 15 zero-days this year that impacted its iOS/iPhone userbase.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/google-fixes-android-zero-day-exploited-in-the-wild-in-targeted-attacks