Android security update includes patch for actively exploited vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-45569 | Memory corruption while parsing the ML IE due to invalid frame content. Memory corruption while parsing the ML IE due to invalid frame content. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-53104 | Out-of-Bounds Write in Linux Kernel UVC Video Driver (CVE-2024-53104) CVE-2024-53104 is an out-of-bounds write (CWE-787) in the Linux kernel's uvcvideo (USB Video Class) driver: uvc_parse_format does not skip frames of type UVC_VS_UNDEFINED, but those frame types were not accounted for when sizing the frames buffer in uvc_parse_streaming. The flaw is triggered when the kernel parses format/frame descriptors from a USB camera device, so a crafted or nonconforming USB video descriptor can corrupt adjacent kernel memory. An attacker with local, low-privileged access (CVSS 3.1: AV:L/AC:L/PR:L, 7.8 High) can gain kernel memory corruption with high impact to confidentiality, integrity and availability, typically yielding local privilege escalation. Any Linux system or Android device running a kernel that ships the UVC driver is in scope, including Debian and other distributions built from affected kernel sources. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV on 2025-02-05, Google fixed it as an actively exploited flaw in the March 2025 Android Security Update, and EPSS currently estimates a 3.4% (88th percentile) probability of exploitation over the next 30 days. Do: Upgrade to a Linux kernel version that contains the uvcvideo fix (apply updated kernel packages from your distribution, e.g. Debian), and for Android devices install the March 2025 Android Security Bulletin patches or later. Follow the CISA KEV required action by applying vendor mitigations or discontinuing use if patches are unavailable. To gauge exposure on unpatched hosts, check whether the UVC driver is loaded (e.g. 'lsmod | grep uvcvideo') and restrict untrusted USB video devices until patched. | 7.8 | 3% | KEV |
| masshundreds of millions of Linux/Android installations potentially carrying the vulnerable driver (Linux kernel runs on billions of devices and the UVC driver… |
Full article536 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The monthly update closes 47 security vulnerabilities in total.
Listen to this article
0:00
Learn more.
Google has addressed a total of 47 security vulnerabilities in its February update for the Android operating system, highlighted by the patching of a critical flaw that has reportedly been under active exploitation.
The primary focus of the security update is CVE-2024-53104, a high-severity vulnerability affecting the USB Video Class (UVC) driver in the Linux kernel. First disclosed in November 2024, the flaw, which has a CVSS score of 7.8, enables privilege escalation, allowing malicious actors to execute arbitrary code or cause device crashes. The issue, traced back to the introduction of Linux kernel version 2.6.26 in 2008, is rooted in the mishandling of video frame parsing — specifically an out-of-bounds write condition within the “uvc_parse_format()” function.
Google’s advisory indicates that the flaw is being exploited in a limited, targeted manner. The exploitation involves a form of “physical” privilege escalation, suggestive of potential use by forensic tools aimed at extracting data from older devices.
In addition to CVE-2024-53104, Qualcomm has patched a critical vulnerability in its WLAN components, designated as CVE-2024-45569, which carries a CVSS score of 9.8. This flaw relates to a memory corruption issue arising from improper validation of array indices during network management frame processing, posing a significant risk of remote code execution. Qualcomm’s chipsets are widely used in Android devices.
Google’s Android security update comprises two patch levels — 2025-02-01 and 2025-02-05 — providing Android partners with flexibility in addressing shared vulnerabilities. The latter patch includes additional remedies for kernel and third-party component vulnerabilities, particularly from vendors such as Arm, Imagination Technologies, MediaTek, and Unisoc.
As always, those using Google Pixel will receive prompt access to the patches, while other manufacturers are often slower to roll out security patches, due to the necessity of tailoring security measures to their own bespoke devices.
You can read the full bulletin here.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Jail time for Maine child in 764 marks turning point in federal law enforcement
Dogged Russia-based botnet dismantled after 23-year run
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-february-2025/