Google warns millions of Android devices could be at risk of attack due to this flaw

app security
(Image credit: Shutterstock.com) (Image credit: Shutterstock.com)

Google has warned that Android devices around the world could be at risk of cyberattacks, partly due to the slow and cumbersome patching process. 

Cybersecurity researchers from Google’s Project Zero team discovered a total of five vulnerabilities affecting the Arm Mali GPU driver. 

The flaws have been grouped under two identifiers - CVE-2022-33917, and CVE-202236449, and they allow threat actors a myriad of options, from accessing free memory sections, to writing outside of buffer bounds. They’ve all gotten a severity score of “medium”. 

More OEMs, slower patches

The flaws have since been patched, but hardware manufacturers are yet to apply these patches on their endpoints. Unlike Apple, which is the sole creator of both hardware, and software, for the iPhone mobile ecosystem, Google is not the only company creating the software and hardware for Android.

Besides Google with its Pixel phone, there is a relatively large number of smartphone manufacturers building Android-powered devices, such as Samsung, LG, Oppo, and many others. All these companies have their own, modified versions of Android, and their own approach to hardware. That said, when a vulnerability is discovered, each original equipment manufacturer (OEM) needs to apply the patch to their own devices. That can take time, as these patches can sometimes conflict with the device’s drivers or other components.

And that’s exactly the problem here. 

The flaws affect Arm’s Mali GPU drivers codenamed Valhall, Bifrost, Midgard, and affect a long list of devices, including the Pixel 7, RealMe GT, Xiaomi 12 Pro, OnePlus 10R, Samsung Galaxy S10, Huawei P40 Pro, and many, many others. The entire list can be found here

Right now, there’s nothing users can do other than wait for their respective manufacturers to apply the patch, as it should be delivered to OEMs in a few weeks.

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
MediaTek
MediaTek reveals host of security vulnerabilities, so patch now
An image of network security icons for a network encircling a digital blue earth.
Industrial networks exposed to attack by faulty Moxa devices
The best free firewall
Palo Alto warns another major firewall hack has been detected
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
A VPN runs on a mobile phone placed on a laptop keyboard
SonicWall firewalls hit by worrying cyberattack
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over