
Those who are lucky will receive the December 2019 Android update this week , which fixes some system and Qualcomm flaws at both levels of the operating system.
According to Google, the flaw deemed most urgent to fix is CVE-2019-2232, which affects Android versions 8.0, 8.1, 9, and 10.
The company says the vulnerability could allow an attacker to cause a “permanent” denial of service ( DoS ) by sending users a specially crafted message. The company doesn’t elaborate on what exactly this alarming description means, and there’s no indication that the flaw has been exploited by a malicious user yet , but it’s unlikely that anyone else would want to find out the hard way.
In total, the update fixes 15 CVEs (2019-12-01) and 5 CVEs (2019-12-05), with another 22 patch items for Qualcomm.
Patch level 2019-12-01
This is the level that affects most devices , not made by Google itself. If the patch level on your phone uses the date '01' next to the month, it means you're getting security updates up to that date, which means all the necessary ones.
Three patches at this level have been rated critical, but for two of them – CVE-2019-2222 and CVE-2019-2223 – this rating only applies to versions 8.0, 8.1, and 9. On Android 10, they are simply important. This could be because Android 10 has additional mitigations, or because it uses Project Mainline, through which some critical updates are applied faster through Google Play.
A flaw, which was recently discovered and secretly patched a while ago via the Play Store, was a hijacking flaw affecting Google's camera app.
