Original topic:

Google finds a zero-day vulnerability in Android, affects Pixel, Xiaomi, Samsung

(Topic created on: 10-05-2019 03:24 PM)
138 Views
KomalJain
★
Options
Others
Google's zero day security researchers have found a critical vulnerability in its Android operating system that would allow hackers to gain access to gain full access to at least 18 smartphones, including its own Pixel smartphones. The company disclosed the exploit just seven days after discovering it adding that the vulnerability has already been used in the wild.

"The bug is a local privilege escalation vulnerability that allows for a full compromise of a vulnerable device.If the exploit is delivered via the Web, it only needs to be paired with a renderer exploit, as this vulnerability is accessible through the sandbox," Google's project zero researcher Maddie Stone said in a post.

In the post Stone said that this vulnerability can be exploited in two ways. First, hackers can target smartphones by making users install untrusted app. Second, hackers can combine the exploit with a second exploit that would target a vulnerability in the code of the Chrome web browser. What's scary is that the exploit requires "little or no per-device customization."

If you not scared enough, there is more. This vulnerability was allegedly used by the Israel based NSO Group, which is famous for its spyware software called Pegasus that can reportedly provide rooted access to iPhones and Android devices.

"I received technical information from TAG and external parties about an Android exploit that is attributed to NSO group...The bug was allegedly being used or sold by the NSO Group," Stone wrote.

Here is a list of phones that are affected by this vulnerability:

-- Pixel 2 with Android 9 and Android 10 preview
-- Huawei P20
-- Xiaomi Redmi 5A
-- Xiaomi Redmi Note 5
-- Xiaomi A1
-- Oppo A3
-- Moto Z3
-- Oreo LG phones
-- Samsung Galaxy S7
-- Samsung Galaxy S8
-- Samsung Galaxy S9

Now the good news. While this exploit works on Pixel and Pixel 2 series smartphones, Pixel 3a series smartphones are immune to it. Google issued a security patch to fix this vulnerabilty Android 3.18, Android 4.4, Android 4.9, however, the Pixel 2 running on the latest security update is still susceptible to it. Google would be issuing a patch to fix this vulnerability in Android's October security patch. It has also notified its partners who will roll out a security update on to the affected devices soon.
4 Comments
Rahuljain123
Active Level 1
Others
great knowledge to share
0 Likes
Anonymous
Not applicable
Others
🤣🤣🤣🤣 ab toh badlana hi pade ga
0 Likes
Others
My Note 9 is safe
0 Likes
Arkhangel
Active Level 5
Others
s9 plus also 😅
0 Likes