ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Security Vulnerabilities in Android Firmware

highVulnerabilityimportance 42
Full article159 words · extracted from schneier.com · click to collapse

Researchers have discovered and revealed 146 vulnerabilities in various incarnations of Android smartphone firmware. The vulnerabilities were found by scanning the phones of 29 different Android makers, and each is unique to a particular phone or maker. They were found using automatic tools, and it is extremely likely that many of the vulnerabilities are not exploitable—making them bugs but not security concerns. There is no indication that any of these vulnerabilities were put there on purpose, although it is reasonable to assume that other organizations do this same sort of scanning and use the findings for attack. And since they’re firmware bugs, in many cases there is no ability to patch them.

I see this as yet another demonstration of how hard supply chain security is.

News article.

Tags: Android, firmware, smartphones, supply chain, vulnerabilities

Posted on November 18, 2019 at 6:33 AM18 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2019/11/security_vulner_20.html