HomeSecurityCritical Android zero-day vulnerability remains unpatched after 6 months

Critical Android zero-day vulnerability remains unpatched after 6 months

Android users are at risk from a zero-day vulnerability in the operating system that affects all makes and models.

The zero-day flaw could affect billions of devices, yet no patch was issued in this month's security updates or in the initial Android 10 builds for Pixel.

zero day

If exploited, the device grants advanced privileges to the hacker, allowing them to use your device as they wish.

White hat hackers warn:

"This vulnerability allows attackers to escalate privileges on vulnerable installations of Google Android. An attacker must first gain the ability to execute low-privileged code on the system in order to exploit this vulnerability."

The issue is caused by a driver called v4l2 (or Video4Linux 2 for completists). It appears to allow attacks by failing to check whether the object they are asked to edit exists. This means they can do whatever they want with elevated privileges.

Critical Android zero-day vulnerability remains unpatched after 6 months

The good news is that for the attack to succeed, the attacker must have your device in their hands.

The vulnerability first surfaced in March and yet, it hasn't been patched through the monthly security updates for Android devices. Google said it's aware of the issue but hasn't yet come up with a fix. As a zero-day vulnerability, Google really should take it seriously.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS