HomeSecurityGoogle: Fixes critical vulnerabilities in Android devices

Google: Fixes critical vulnerabilities in Android devices

Google has released the February 2022 security updates for Android, which, among other things, fix two critical vulnerabilities. One of them allows an attacker to gain more privileges on the vulnerable device (remote escalation of privilege) without requiring user interaction.

See also: Google One VPN: The service is available to iPhone and iPad users

Google: Fixes critical vulnerabilities in Android devices
Google: Fixes critical vulnerabilities in Android devices

The vulnerability is known as CVE-2021-39675 and is classified as “Critical.” It only affects Android 12, the latest version of the operating system.

These types of vulnerabilities are typically exploited by spyware who discover them themselves and use them in mobile operating systems. However, in this case, Google has not found evidence that the vulnerability has been used in attacks.

The second critical bug that Google is fixing with Android security updates is CVE-2021-30317, which affects a closed-source component from Qualcomm. This means that it only affects Android devices that use hardware from that vendor.

See also: Roaming Mantis Android malware campaign appears in Europe

Google Android vulnerabilities

As Google explains in the bulletin: “The severity rating of a vulnerability is based on the impact that exploitation of that vulnerability would potentially have on a vulnerable device.”

Technical details about the vulnerabilities are not available at this time, as Android security updates typically take several months to reach a large percentage of users. This is because vendors have to bundle them and release them separately for each device model.

The only exception to this practice is Google's Pixel devices . All models from the "3a" to the "6 Pro" are already receiving the February 2022 security updates.

See also: Medusa android banking trojan: Shows increased infection rates

Generally, this month's fixes are for Android 10, 11, and 12, so if your phone is running an older version, you're not covered. Such a device should be considered a major security risk.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS