Google Addresses New Android Kernel Flaw Under Active Exploitation

Google has recently tackled a critical security issue affecting the Android kernel, which it acknowledges has been actively exploited in real-world scenarios.

Designated as CVE-2024-36971, this vulnerability enables remote code execution within the kernel. The company’s August 2024 Android security bulletin indicates that this flaw may be subject to selective, targeted exploitation.

As is customary, Google did not provide further details about the specific nature of the attacks or identify the perpetrators. It is currently unclear whether Pixel devices are also vulnerable to this issue. However, Clement Lecigne from Google’s Threat Analysis Group (TAG) has highlighted that this vulnerability is likely being used by commercial spyware firms for targeted attacks on Android devices.

The August security update addresses 47 distinct vulnerabilities, including those found in components from Arm, Imagination Technologies, MediaTek, and Qualcomm. Additionally, the update resolves 12 privilege escalation issues, one information disclosure vulnerability, and one denial-of-service (DoS) flaw affecting the Android Framework.

In June 2024, Google disclosed an elevation of privilege vulnerability in Pixel Firmware (CVE-2024-32896), which had been exploited in targeted attacks. The company later informed The Hacker News that this issue affected not only Pixel devices but the broader Android ecosystem, and they are collaborating with OEM partners to implement necessary fixes.

Previously, Google also resolved two security vulnerabilities in the bootloader and firmware components (CVE-2024-29745 and CVE-2024-29748) that had been exploited by forensic firms to extract sensitive information.

In related news, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-0824, a remote code execution vulnerability affecting Microsoft COM for Windows, to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion mandates that federal agencies apply fixes by August 26, 2024. This action follows a Cisco Talos report indicating that the flaw was utilized by the Chinese state-sponsored group APT41 in a cyber attack on an unnamed Taiwanese government-linked research institute to achieve local privilege escalation.

More Articles & Posts