A proof-of-concept (PoC) exploit for a serious vulnerabilityaffecting at least seven Android phone manufacturers (OEMs)has been released on GitHub. However, the exploit requires local access.

The vulnerability for which the exploit was created is tracked as CVE-2023-45779 and was discovered by 's Red Team X Meta in September of last year. It was fixed in the December 2023 Android security update, without providing technical details.
The vulnerability is due to insecure signing of APEX modules that use test keys, allowing attackers to push malicious updates to platform and gain more privileges.
See also: Ivanti warns of two new Connect Secure vulnerabilities
Although local access is required to exploit the vulnerability, it shows that there are weaknesses in the Compatibility Test Suite (CTS) and the Android Open Source Project (AOSP), which Google plans to address in the upcoming Android 15 release.
Devices that have received the Android update level 2023-12-05 are safe.
Insecure APEX signing
Meta's Tom Hebb explained that the problem is related to the signing of APEX modules using public test keys from AOSP.
APEX modules allow OEMs to push updates to specific system without issuing a full over-the-air (OTA) update. The modules must be signed with a private key known only to the OEM and generated during the build process. Using the same public key found in the Android source code build tree means that anyone could create updates to critical system components.

Cybercriminals malicious updates that they can use to gain elevated privileges on the device, bypassing existing security mechanisms. In some cases, they can take full control of the Android phone.
See also: Vulnerability in glibc allows root access on Linux distributions
The CVE-2023-45779 vulnerability affects multiple OEMs, including ASUS (tested on Zenfone 9), Microsoft (Surface Duo 2), Nokia (G50), Nothing (Phone 2), VIVO (X90 Pro), Lenovo (Tab M10 Plus), and Fairphone (5).
The models above are the ones that were tested, but many other (if not all) models from these seven manufacturers are likely vulnerable to CVE-2023-45779.
Meta researchers also tested phone models from other manufacturers. The following were not affected: Google (Pixel), Samsung (Galaxy S23), Xiaomi (Redmi Note 12), OPPO (Find X6 Pro), Sony (Xperia 1 V), Motorola (Razr 40 Ultra), and OnePlus (10T).
Exploit available for Android vulnerability
Researchers released an exploit for the CVE-2023-45779 vulnerability on GitHub, but its availability is not particularly worrisome.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Exploiting the flaw requires physical access to the deviceand some expertise in using 'adb shell'. Therefore, the PoC is primarily intended for research.
See also: Chinese hackers exploit zero-day vulnerabilities in VPNs
However, there is always the risk of the exploit being used as part of an exploit chain to escalate privileges on an already compromised device. Hackers are always looking for ways to infiltrate devices. Therefore, users are urged to get the update to protect their devices.

How can users protect their devices?
Users should regularly update their operating system and applications. These updates often include security that can protect the device from security holes, such as the above vulnerability.
It is also recommended to use reliable security software. This can help detect and protect against malware and other threats.
Great care should also be taken with the applications that users download and install on their devices. They should always check the ratings and comments of other users, as well as the permissions an application requests before installing.
Finally, it is important for them to use strong passwords and enable encryption on their device. This can help protect their personal and sensitive data from being compromised.
Source: www.bleepingcomputer.com
