Google fixes "critical" Android 12 security flaw

Android Logo
(Image credit: Google)

Google has fixed a critical security flaw in Android 12 which could have allowed crooks access to the target endpoint without user interaction.

In its February 2022 Android Security Bulletin, Google says that the flaw, tracked as CVE-2021-39675, is a “critical security vulnerability in the System component that could lead to remote escalation of privilege with no additional execution privileges needed.”

Other than that, there’s not much detail in the blog itself, however The Register spotted a source-level change in Android’s wireless near-field communication (NFC) code, that forces the code to ensure a size parameter isn’t too large. The publication also suspects Google decided to keep the whole thing hush-hush as it’s still in the middle of rolling out the patches.

Additional flaws discovered

Unlike iOS, which is a fully centralized operating system where Apple controls the patches, most Android makers have their own sub-brand of the OS, meaning all of them have to prepare patches for their devices separately. Given that Google develops Android, Google-made phones ( such as the Pixel 6) will be among the first to receive this patch. 

Still, Google notifies its partners of newly discovered vulnerabilities a month before publicizing anything, so it’s safe to assume that other vendors will be close behind, at least for their flagship models. 

The announcement has also listed five other high-severity flaws found in the System component, that were patched. That includes privilege elevation bugs in Android 11 and 12, as well as denial-of-service flaws in Android 10 and 11. 

Other than that, Google has also identified five high-severity flaws in the Android Framework component, four high-severity bugs in the Media Framework, and two MediaProvider flaws fixed through Google Play updates. 

To check for updates manually, Android users can navigate to Settings > Software Update, which is located at the very bottom of the menu. 

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
MediaTek
MediaTek reveals host of security vulnerabilities, so patch now
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Digital image of a lock.
Fortinet flags some worrying security bugs coming back from the dead
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all