HomeSecurityGoogle: Fixes exploitable vulnerability in Android kernel

Google: Fixes exploitable vulnerability in Android kernel

A fix for an actively exploited Linux kernel vulnerability has been released by Google as part of the May security patch for Android

See also: Google: Fires another AI researcher who questioned findings
Google

The flaw, identified as CVE-2021-22600, is a privilege escalation bug in the Linux kernel that can be exploited by threat actors via local access. Since Android uses a modified Linux kernel, the vulnerability also affects the operating system.

Google researchers discovered the vulnerability in January and also presented a patch that was responsibly disclosed to Linux vendors. However, it took several months for this vulnerability to be patched in Google's Android operating system.

In April, CISA revealed that this vulnerability was being actively exploited in attacks and added it to the “List of Known Exploitable Vulnerabilities.” In its May Android Security Bulletin, Google confirms that “ CVE-2021-22600 may be subject to limited, targeted exploitation.”

See also: Which Androids emit more radiation than allowed by the FCC

Google: Fixes exploitable vulnerability in Android kernel

It is unclear how the vulnerability is being used in attacks, but it is likely used to execute privileged commands and spread laterally through Linux systems on corporate networks.

Recent Android versions have incorporated increasingly strict permissions, making it difficult for malware to obtain the permissions required for advanced features.

A second potential use of this vulnerability is device rooting tools that users install and activate themselves to gain root privileges on the device.

Please note that the patch for CVE-2021-22600 and all third-party patches are available in the security patch level 2022-05-05 and not in the first security patch level released on May 1, 2022.

However, all of these fixes are still being incorporated into next month's first security patch level, which is scheduled to be released on June 1, 2022.

See also: Google acquires microLED startup Raxium to strengthen hardware team

Android

If you are using Android 9 or earlier, this security patch does not apply to your device and you should upgrade to a more recent version of the Android operating system for security.

Those using Google Pixel received additional patches this month, with one of them affecting only the latest Pixel 6 Pro series that uses the Titan-M chip.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS