HomeSecurityAndroid: Code update makes n-days just as dangerous as zero-days

Android: Code update makes n-days as dangerous as zero-days

Google has published its annual zero-day vulnerability report, presenting exploitation statistics from 2022 and highlighting a long-standing problem in the Android platform that exploits n-day flaws over a long period of time, increasing their value and risk.

See also: Zimbra fixes serious zero-day vulnerability

Android

More specifically, Google's report highlights the problem of n-day vulnerabilities that act as zero-days for risk factors in Android.

The problem stems from the complexity of the Android ecosystem, which involves multiple steps between the vendor (Google) and phone manufacturers. This leads to significant discrepancies in security update intervals between different device models, short support periods, mixed responsibilities, and other issues.

A zero-day is one of the most dangerous threats in the world of cybersecurity. This is because they are vulnerabilities that software vendors are not yet aware of or have not yet released patches to fix them. This creates a “window” for hackers to exploit the vulnerabilities before they are fixed. The issue of zero-days is particularly acute on Android, due to the size and complexity of its ecosystem. However, an n-day vulnerability is one that is publicly known, with patch .

For example, when a bug is known in Android before Google, it is called a zero-day. However, when Google learns about it, it becomes an n-day, where n represents the number of days since it was published.

See also: Apple fixes another zero-day vulnerability

zero day

Google warns that attackers can exploit vulnerabilities in devices that haven't been patched for months. By using either known exploits or devising their own, attackers are threatening the security of devices. This is despite the fact that Google and other vendors have already released patches to fix these vulnerabilities.

This happens when there are gaps in the code update, as Google or other vendors fix a bug, but device manufacturers take months to incorporate it into their own versions of the Android operating system.

“ These gaps between upstream vendors and downstream manufacturers allow n-days – vulnerabilities that are publicly known – to operate as 0-days because no patch is immediately available to the user and their only defense is to stop using the device ,” Google’s report explains .

“While these gaps exist in most upstream/downstream relationships, they are more widespread and larger in Android.“

See also: Endpoint Manager Mobile: Ivanti fixes zero-day vulnerability

In 2022, several such issues affected Android, the most notable being CVE-2022-38181, a vulnerability in the ARM Mali GPU. This bug was reported to the Android Security Team in July 2022 and was initially considered “unpatchable.” However, in October 2022, it was patched by ARM and eventually incorporated into the April 2023 Android security update.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS