Google Warns of New Android 0-Day Vulnerability Under Active Targeted Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-11261 | Local Privilege Escalation via Memory Corruption in Qualcomm Snapdragon Chipsets CVE-2020-11261 is an improper input validation flaw (CWE-20/CWE-787, resulting in memory corruption/out-of-bounds writes) in the memory-allocation handling of firmware across a wide range of Qualcomm Snapdragon chipsets. It is triggered when a user application requests a memory allocation of a huge size and the affected component fails to properly return an error; a local attacker — such as a malicious or compromised app already running on the device — can leverage this to escalate privileges. Successful exploitation yields elevated privileges with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, local attack vector, no user interaction required). Affected platforms span the Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, Voice & Music, and Wearables product lines, including widely deployed entry-level mobile SoCs and connectivity chips. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-12-01, confirming in-the-wild exploitation; it was quietly patched in Android security updates alongside related Arm and Qualcomm zero-days, no public PoC is known, and EPSS estimates a 1.8% probability of exploitation in the next 30 days. Do: Apply updated Qualcomm firmware and driver packages per the vendor advisory, as required by CISA's KEV listing, and ensure Android devices receive the OEM security updates containing the fix. Inventory devices built on the listed chipsets (e.g., APQ8009, APQ8017, APQ8053, APQ8096AU) and confirm they run patched builds; there is no workaround beyond patching, since a local malicious app is sufficient to trigger the flaw. | 7.8 | 2% | KEV |
| mass≈1 billion+ devices (affected Snapdragon SoC families ship in entry-level Android phones and IoT/automotive hardware at massive volume) | |
| CVE-2021-0889 | In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296 NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2021-1048 | Use-After-Free Privilege Escalation in Android Kernel (CVE-2021-1048) CVE-2021-1048 is a use-after-free (CWE-416) in ep_loop_check_proc of eventpoll.c — the Android kernel's epoll event-notification code — that can corrupt kernel memory. A local attacker (e.g., a malicious app with no special permissions) can trigger the flaw, and no user interaction is required, yielding local escalation of privilege to kernel level. Any Android device running an unpatched Android kernel is affected. The flaw is being actively exploited: it is in CISA's Known Exploited Vulnerabilities Catalog (added 2022-05-23) and reporting indicates Google fixed it as a zero-day used in targeted attacks, with coverage tying Android kernel zero-days to Cytrox/Intellexa Predator spyware campaigns. EPSS currently puts the 30-day exploitation probability at ~1.0%, but the KEV listing and in-the-wild targeting make patching urgent. Do: Apply updates per vendor instructions (CISA KEV required action): install the latest Android security/kernel updates from Google or your device OEM — Google's advisories indicate the complete fix shipped in the February 2022 Android security bulletin (2022-02-05 patch level), following the initial January 2022 fix. Fleet administrators should verify devices' security patch levels and prioritize high-value/targeted users, since observed exploitation has been targeted (spyware-linked) rather than mass-scale. No public PoC is known and ransomware use is unknown, but defenders should hunt for signs of local privilege escalation on unpatched fleets. | 7.8 | 1% | KEV |
| mass≈3 billion Android devices worldwide (Android's global active-device installed base; unpatched share unknown) | |
| CVE-2021-1905 +1 in the same advisory: …1906 | Use-After-Free in Qualcomm Snapdragon Chipsets Allows Local Privilege Escalation CVE-2021-1905 is a use-after-free flaw (CWE-416) in firmware for a broad set of Qualcomm chipsets, caused by improper handling of memory mapping of multiple processes simultaneously. A local attacker who can already run low-privileged code on an affected device can trigger the stale-memory access, and with high confidentiality, integrity, and availability impact (CVSS 3.1 7.8, local vector, low privileges), successful exploitation can yield arbitrary code execution and privilege escalation. It affects devices built on Snapdragon platforms across the Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, Voice & Music, and Wearables lines, with CISA listing chipset firmware including APQ8009, APQ8017, APQ8053, APQ8096AU, AQT1000, AR8031/8035/8151, and CSRA6620/6640. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, and contemporaneous reporting described a Qualcomm zero-day under active targeted attacks that was quietly patched in that month's Android security updates, confirming exploitation in the wild. No public proof-of-concept is known, and EPSS estimates about a 1.5% probability of exploitation in the next 30 days (73rd percentile). Do: Apply the updated chipset firmware/drivers per Qualcomm's security advisory, and for phones and tablets install the latest Android monthly security update (November 2021 or later, per related reporting) and verify the device's security patch level. Because exploitation requires local code execution (AV:L), prioritize patching endpoints used by high-risk or targeted users and check with automotive, IoT, and networking equipment vendors for updated firmware. No workaround is documented, so treat KEV-listed, unpatched devices as at risk. | 7.8 group max | 2% | KEV |
| masshundreds of millions to billions of deployed devices (est.) | |
| CVE-2021-1975 +1 in the same advisory: …1924 | Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2021-28663 +1 in the same advisory: …28664 | Use-After-Free Privilege Escalation in Arm Mali GPU Kernel Driver CVE-2021-28663 is a use-after-free flaw in the Arm Mali GPU kernel driver, caused by mishandled GPU memory operations in the Midgard, Bifrost, and Valhall driver families. An attacker who can run code with limited privileges on a device can trigger the flaw through GPU memory operations, gaining local privilege escalation or disclosure of sensitive information (CISA's CVSS scoring uses a network attack vector). The bug is present in Midgard drivers r4p0 through r30p0, Bifrost r0p0 through r28p0 (before r29p0), and Valhall r19p0 through r28p0 (before r29p0), which ship on Android devices using Mali GPUs. It was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and was patched as part of Android security updates after Google reported it being actively exploited in targeted attacks; a public proof of concept is available on GitHub. Do: Apply Android security updates (November 2021 patch level or later) and OEM/Arm driver updates per vendor instructions, upgrading the Bifrost and Valhall GPU kernel drivers to r29p0 or later; for Midgard, move beyond the affected r4p0-r30p0 range to the latest available driver release. Organizations managing Android fleets should check device patch levels and Mali driver versions via device management tooling and prioritize this because it is on the CISA KEV list with exploitation observed in targeted attacks. Where patching is delayed, limit exposure for low-privileged users on affected devices, as exploitation requires the ability to run code on the device. | 8.8 | 12% | KEV PoC |
| masshundreds of millions of Android devices with Mali GPUs (Midgard/Bifrost/Valhall), plus any other systems running affected Mali driver versions |
Full article350 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananNov 03, 2021
Google has rolled out its monthly security patches for Android with fixes for 39 flaws, including a zero-day vulnerability that it said is being actively exploited in the wild in limited, targeted attacks.
Tracked as CVE-2021-1048, the zero-day bug is described as a use-after-free vulnerability in the kernel that can be exploited for local privilege escalation. Use-after-free issues are dangerous as it could enable a threat actor to access or referencing memory after it has been freed, leading to a "write-what-where" condition that results in the execution of arbitrary code to gain control over a victim's system.
"There are indications that CVE-2021-1048 may be under limited, targeted exploitation," the company noted in its November advisory without revealing technical details of the vulnerability, the nature of the intrusions, and the identities of the attackers that may have abused the flaw.
Also remediated in the security patch are two critical remote code execution (RCE) vulnerabilities — CVE-2021-0918 and CVE-2021-0930 — in the System component that could allow remote adversaries to execute malicious code within the context of a privileged process by sending a specially-crafted transmission to targeted devices.
Two more critical flaws, CVE-2021-1924 and CVE-2021-1975, affect Qualcomm closed-source components, while a fifth critical vulnerability in Android TV (CVE-2021-0889) could permit an attacker in close proximity to silently pair with a TV and execute arbitrary code with no privileges or user interaction required.
With the latest round of updates, Google has addressed a total of six zero-days in Android since the start of the year —
- CVE-2020-11261 (CVSS score: 8.4) - Improper input validation in Qualcomm Graphics component
- CVE-2021-1905 (CVSS score: 8.4) - Use-after-free in Qualcomm Graphics component
- CVE-2021-1906 (CVSS score: 6.2) - Detection of error condition without action in Qualcomm Graphics component
- CVE-2021-28663 (CVSS score: 8.8) - Mali GPU Kernel Driver allows improper operations on GPU memory
- CVE-2021-28664 (CVSS score: 8.8) - Mali GPU Kernel Driver elevates CPU RO pages to writable
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/11/google-warns-of-new-android-0-day.html