HomeVulnerabilityNewest Android Patch Replace Consists of Repair for Newly Actively Exploited Flaw

Newest Android Patch Replace Consists of Repair for Newly Actively Exploited Flaw

Google has rolled out month-to-month security patches for Android to handle numerous flaws, together with a zero-day bug that it mentioned might have been exploited within the wild.

Tracked as CVE-2023-35674, the high-severity vulnerability is described as a case of privilege escalation impacting the Android Framework.

“There are indications that CVE-2023-35674 could also be below restricted, focused exploitation,” the corporate mentioned in its Android Safety Bulletin for September 2023 with out delving into further specifics.

The replace additionally addresses three different privilege escalation flaws in Framework, with the search large noting that probably the most extreme of those points “might result in native escalation of privilege with no further execution privileges wanted” sans any consumer interplay.

Google mentioned it has additional plugged a crucial security vulnerability within the System part that might result in distant code execution with out requiring interplay on the a part of the sufferer.

“The severity evaluation is predicated on the impact that exploiting the vulnerability might have on an affected gadget, assuming the platform and repair mitigations are turned off for improvement functions or if efficiently bypassed,” it added.

See also  Citrix warns admins to manually mitigate PuTTY SSH consumer bug

In complete, Google has mounted 14 flaws within the System module and two shortcomings within the MediaProvider part, the latter of which shall be delivered as a Google Play system replace.

- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular