ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Google Warns of New Android 0-Day Vulnerability Under Active Targeted Attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-11261
Local Privilege Escalation via Memory Corruption in Qualcomm Snapdragon Chipsets

CVE-2020-11261 is an improper input validation flaw (CWE-20/CWE-787, resulting in memory corruption/out-of-bounds writes) in the memory-allocation handling of firmware across a wide range of Qualcomm Snapdragon chipsets. It is triggered when a user application requests a memory allocation of a huge size and the affected component fails to properly return an error; a local attacker — such as a malicious or compromised app already running on the device — can leverage this to escalate privileges. Successful exploitation yields elevated privileges with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, local attack vector, no user interaction required). Affected platforms span the Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, Voice & Music, and Wearables product lines, including widely deployed entry-level mobile SoCs and connectivity chips. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-12-01, confirming in-the-wild exploitation; it was quietly patched in Android security updates alongside related Arm and Qualcomm zero-days, no public PoC is known, and EPSS estimates a 1.8% probability of exploitation in the next 30 days.

Do: Apply updated Qualcomm firmware and driver packages per the vendor advisory, as required by CISA's KEV listing, and ensure Android devices receive the OEM security updates containing the fix. Inventory devices built on the listed chipsets (e.g., APQ8009, APQ8017, APQ8053, APQ8096AU) and confirm they run patched builds; there is no workaround beyond patching, since a local malicious app is sufficient to trigger the flaw.

7.82% KEV
  • Qualcomm APQ8009 firmware
  • Qualcomm APQ8009W firmware
  • Qualcomm APQ8017 firmware
  • +9 more
mass≈1 billion+ devices (affected Snapdragon SoC families ship in entry-level Android phones and IoT/automotive hardware at massive volume)
CVE-2021-0889
+2 in the same advisory: …0930 …0918
In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow.

In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296

NVD description · AI analysis pending
9.8
group max
2%
  • google android
CVE-2021-1048
Use-After-Free Privilege Escalation in Android Kernel (CVE-2021-1048)

CVE-2021-1048 is a use-after-free (CWE-416) in ep_loop_check_proc of eventpoll.c — the Android kernel's epoll event-notification code — that can corrupt kernel memory. A local attacker (e.g., a malicious app with no special permissions) can trigger the flaw, and no user interaction is required, yielding local escalation of privilege to kernel level. Any Android device running an unpatched Android kernel is affected. The flaw is being actively exploited: it is in CISA's Known Exploited Vulnerabilities Catalog (added 2022-05-23) and reporting indicates Google fixed it as a zero-day used in targeted attacks, with coverage tying Android kernel zero-days to Cytrox/Intellexa Predator spyware campaigns. EPSS currently puts the 30-day exploitation probability at ~1.0%, but the KEV listing and in-the-wild targeting make patching urgent.

Do: Apply updates per vendor instructions (CISA KEV required action): install the latest Android security/kernel updates from Google or your device OEM — Google's advisories indicate the complete fix shipped in the February 2022 Android security bulletin (2022-02-05 patch level), following the initial January 2022 fix. Fleet administrators should verify devices' security patch levels and prioritize high-value/targeted users, since observed exploitation has been targeted (spyware-linked) rather than mass-scale. No public PoC is known and ransomware use is unknown, but defenders should hunt for signs of local privilege escalation on unpatched fleets.

7.81% KEV
  • Google Android (kernel)
mass≈3 billion Android devices worldwide (Android's global active-device installed base; unpatched share unknown)
CVE-2021-1905
+1 in the same advisory: …1906
Use-After-Free in Qualcomm Snapdragon Chipsets Allows Local Privilege Escalation

CVE-2021-1905 is a use-after-free flaw (CWE-416) in firmware for a broad set of Qualcomm chipsets, caused by improper handling of memory mapping of multiple processes simultaneously. A local attacker who can already run low-privileged code on an affected device can trigger the stale-memory access, and with high confidentiality, integrity, and availability impact (CVSS 3.1 7.8, local vector, low privileges), successful exploitation can yield arbitrary code execution and privilege escalation. It affects devices built on Snapdragon platforms across the Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, Voice & Music, and Wearables lines, with CISA listing chipset firmware including APQ8009, APQ8017, APQ8053, APQ8096AU, AQT1000, AR8031/8035/8151, and CSRA6620/6640. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, and contemporaneous reporting described a Qualcomm zero-day under active targeted attacks that was quietly patched in that month's Android security updates, confirming exploitation in the wild. No public proof-of-concept is known, and EPSS estimates about a 1.5% probability of exploitation in the next 30 days (73rd percentile).

Do: Apply the updated chipset firmware/drivers per Qualcomm's security advisory, and for phones and tablets install the latest Android monthly security update (November 2021 or later, per related reporting) and verify the device's security patch level. Because exploitation requires local code execution (AV:L), prioritize patching endpoints used by high-risk or targeted users and check with automotive, IoT, and networking equipment vendors for updated firmware. No workaround is documented, so treat KEV-listed, unpatched devices as at risk.

7.8
group max
2% KEV
  • Qualcomm APQ8009 firmware
  • Qualcomm APQ8009W firmware
  • Qualcomm APQ8017 firmware
  • +9 more
masshundreds of millions to billions of deployed devices (est.)
CVE-2021-1975
+1 in the same advisory: …1924
Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn

Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

NVD description · AI analysis pending
9.8
group max
<1%
  • qualcomm apq8009 firmware
  • qualcomm apq8009w firmware
  • qualcomm apq8017 firmware
  • +1 more
CVE-2021-28663
+1 in the same advisory: …28664
Use-After-Free Privilege Escalation in Arm Mali GPU Kernel Driver

CVE-2021-28663 is a use-after-free flaw in the Arm Mali GPU kernel driver, caused by mishandled GPU memory operations in the Midgard, Bifrost, and Valhall driver families. An attacker who can run code with limited privileges on a device can trigger the flaw through GPU memory operations, gaining local privilege escalation or disclosure of sensitive information (CISA's CVSS scoring uses a network attack vector). The bug is present in Midgard drivers r4p0 through r30p0, Bifrost r0p0 through r28p0 (before r29p0), and Valhall r19p0 through r28p0 (before r29p0), which ship on Android devices using Mali GPUs. It was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and was patched as part of Android security updates after Google reported it being actively exploited in targeted attacks; a public proof of concept is available on GitHub.

Do: Apply Android security updates (November 2021 patch level or later) and OEM/Arm driver updates per vendor instructions, upgrading the Bifrost and Valhall GPU kernel drivers to r29p0 or later; for Midgard, move beyond the affected r4p0-r30p0 range to the latest available driver release. Organizations managing Android fleets should check device patch levels and Mali driver versions via device management tooling and prioritize this because it is on the CISA KEV list with exploitation observed in targeted attacks. Where patching is delayed, limit exposure for low-privileged users on affected devices, as exploitation requires the ability to run code on the device.

8.812% KEV PoC
  • Arm Bifrost GPU kernel driver r0p0 through r28p0 (versions before r29p0)
  • Arm Valhall GPU kernel driver r19p0 through r28p0 (versions before r29p0)
  • Arm Midgard GPU kernel driver r4p0 through r30p0
masshundreds of millions of Android devices with Mali GPUs (Midgard/Bifrost/Valhall), plus any other systems running affected Mali driver versions
Full article350 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 03, 2021

Google has rolled out its monthly security patches for Android with fixes for 39 flaws, including a zero-day vulnerability that it said is being actively exploited in the wild in limited, targeted attacks.

Tracked as CVE-2021-1048, the zero-day bug is described as a use-after-free vulnerability in the kernel that can be exploited for local privilege escalation. Use-after-free issues are dangerous as it could enable a threat actor to access or referencing memory after it has been freed, leading to a "write-what-where" condition that results in the execution of arbitrary code to gain control over a victim's system.

"There are indications that CVE-2021-1048 may be under limited, targeted exploitation," the company noted in its November advisory without revealing technical details of the vulnerability, the nature of the intrusions, and the identities of the attackers that may have abused the flaw.

Also remediated in the security patch are two critical remote code execution (RCE) vulnerabilities — CVE-2021-0918 and CVE-2021-0930 — in the System component that could allow remote adversaries to execute malicious code within the context of a privileged process by sending a specially-crafted transmission to targeted devices.

Two more critical flaws, CVE-2021-1924 and CVE-2021-1975, affect Qualcomm closed-source components, while a fifth critical vulnerability in Android TV (CVE-2021-0889) could permit an attacker in close proximity to silently pair with a TV and execute arbitrary code with no privileges or user interaction required.

With the latest round of updates, Google has addressed a total of six zero-days in Android since the start of the year —

  • CVE-2020-11261 (CVSS score: 8.4) - Improper input validation in Qualcomm Graphics component
  • CVE-2021-1905 (CVSS score: 8.4) - Use-after-free in Qualcomm Graphics component
  • CVE-2021-1906 (CVSS score: 6.2) - Detection of error condition without action in Qualcomm Graphics component
  • CVE-2021-28663 (CVSS score: 8.8) - Mali GPU Kernel Driver allows improper operations on GPU memory
  • CVE-2021-28664 (CVSS score: 8.8) - Mali GPU Kernel Driver elevates CPU RO pages to writable

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/11/google-warns-of-new-android-0-day.html