ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google fixes a critical Android RCE flaw in the System component

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-0516
+2 in the same advisory: …0507 …0521
In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free.

In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-181660448

NVD description · AI analysis pending
9.8
group max
2%
  • google android
CVE-2021-0607
+3 in the same advisory: …0608 …0571 …0565
In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data due to a missing bounds check.

In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-180950209

NVD description · AI analysis pending
7.8
group max
<1%
  • google android
Full article249 words · extracted from securityaffairs.com · click to collapse

Google’s June security bulletin addresses more than 90 vulnerabilities in Android and Pixel devices, including a Critical RCE (CVE-2021-0507).

Google’s June security bulletin addresses more than 90 vulnerabilities in Android and Pixel devices, including a Critical RCE tracked as CVE-2021-0507 that could allow to take over a device.

“The most severe vulnerability in this section could enable a remote attacker using a specially crafted transmission to execute arbitrary code within the context of a privileged process.” reads the Android Security Bulletin.

The CVE-2021-0507 resides in the System component of the Android OS, an attacker could exploit the flaw by using a specially crafted transmission and execute arbitrary code within the context of a privileged process.

Google also addressed a critical elevation-of-privilege (EoP) issue in the System component tracked as CVE-2021-0516. The remaining flaws in the System component are rated as high severity.

Google fixed multiple high-severity EoP vulnerabilities in other components, including the Media Framework, the System, and the Kernel.

Google also fixed several high-severity information-disclosure issues for Android, including a local information disclosure tracked as CVE-2021-0521.

The IT giant addressed a total of 43 security flaws in multiple components, including Android runtime, Framework, Media Framework, System, kernel components and Pixel components.

The most severe issues of them are CVE-2021-0607 and CVE-2021-0608 EoP issues in Pixel components, the CVE-2021-0565 EoP issue in Media Framework and the CVE-2021-0571.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, mobile)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/118761/security/android-rce.html