Google has patched 62 vulnerabilities in Android, including two zero-days that are actively being exploited in attacks, tracked as CVE-2024-53197 and CVE-2024-53150.
CVE-2024-53197 is a privilege escalation flaw found in the USB audio sub-component of the Linux Kernel. Local attackers are able to exploit the bug to access sensitive information on devices without any user interaction.
It does not yet have a CVSS rating, but according to researchers at Malwarebytes Labs, this was the link between two other vulnerabilities — CVE-2024-50302 and CVE-2024-53104 — which enabled law enforcement in Serbia to unlock a student activist’s device using Cellebrite forensic tools, before attempting to install spyware.
Lägg ned diskussionen om att Android är lika säkert som iOS – de spelar inte i samma liga
Så var det dags igen – ett stort antal appar i den officiella butiken för Android har visat sig innehålla bedräglig, farlig kod och precis som vanligt så upptäcks de apparna långt efter det att de har laddats upp till…
0 kommentarer