Saturday, 04 May 2024

 

 

LATEST NEWS Another jolt to Akali Dal Badal, Aam Aadmi Party gains more strength in Amritsar Lok Sabha constituency Mann's mega road show in Patiala, campaigned for Dr Balbir, said 'Punjab banega hero, es baar 13-0' Harpratap Ajnala roared in favor of Gurjeet Singh Aujla 13 Best Maahi Khan Web Series List (Updated 2024)| 5 Dariya News Erstwhile SAD govt instrumental in developing Greater Mohali area and bringing in international airport, institutions and IT sector : Sukhbir Singh Badal Ankur Jain Net Worth [May 2024]: Know the Income & Wealth Details of American Entrepreneur Nearly 300 people, including Congress Secretary and Joint Secretary, joined BJP DEO Sakshi Sawhney holds meeting to finalize arrangements for smooth nomination process DEO Sakshi Sawhney chairs meeting with political parties regarding filling of nominations DEO Sakshi Sawhney chairs meeting with political parties regarding filling of nominations Ludhiana administration ensuring smooth and hassle-free wheat procurement season: Sakshi Sawhney BJP will end reservation if assumes power once again: Partap Singh Bajwa Ludhiana extends red carpet welcome to Raja Warring iLEAD’s Managedia 2024 Witnesses 45 Colleges Participating in 40+ Events With 4000+ Footfalls Voting to Take Place in Haryana on May 25 - Chief Electoral Officer, Sh. Anurag Agarwal DC Ashika Jain Boosts the Morale of Meritorious Students of Class 10 and 10+2 of Govt Schools Yash Birla Net Worth 2024: Know the Fortune of Indian Industrialists Yash Birla 4th International Conference on Computational Methods in Science & Technology organised by CGC Landran DEO Srinagar Dr. Bilal Mohi-Ud-Din organizes ‘Jashn e Jugalbandi’ under SVEEP at historical Polo View Market DC Bandipora Shakeel-ul-Rehman Rather embarks on 02-day extensive field tour to Gurez Chief Secretary Atal Dulloo reviews IT Deptts' initiatives aimed at enhancing citizen services, govt efficiency

 

Surveillance vendor targeted Samsung smartphones with zero-day bugs : Google

Google, New Delhi, Sundar Pichai, Android Open Source Project, AOSP
Listen to this article

Web Admin

Web Admin

5 Dariya News

New Delhi , 11 Nov 2022

Google has warned that a commercial surveillance vendor was exploiting three zero-day security vulnerabilities in new Samsung smartphones that could have been exploited to steal users' data.All three vulnerabilities were in the manufacturer's custom components rather than in the Android Open Source Project (AOSP) platform or the Linux kernel.

"It's also interesting to note that 2 out of the 3 vulnerabilities were logic and design vulnerabilities rather than memory safety," said Maddie Stone, Project Zero."While we understand that Samsung has yet to annotate any vulnerabilities as in-the-wild, going forward, Samsung has committed to publicly sharing when vulnerabilities may be under limited, targeted exploitation, as part of their release notes," Stone added in a blog post.

"We hope that, like Samsung, others will join their industry peers in disclosing when there is evidence to suggest that a vulnerability is being exploited in-the-wild in one of their products".The Google Threat Analysis Group (TAG) obtained a partial exploit chain for Samsung devices that it believes belonged to a commercial surveillance vendor.

"All 3 vulnerabilities are within Samsung custom components, including a vulnerability in a Java component," said the team.The exploit sample targeted Samsung phones running kernel 4.14.113 with the Exynos SOC.

"Samsung phones run one of two types of SOCs depending on where they're sold. For example the Samsung phones sold in the United States, China, and a few other countries use a Qualcomm SOC and phones sold in most other places (example Europe and Africa) run an Exynos SOC," said the Google team.

Examples of Samsung phones that were running kernel 4.14.113 in late 2020 (when this sample was found) include the S10, A50, and A51 smartphones, the team added."The analysis of this exploit chain has provided us with new and important insights into how attackers are targeting Android devices. It highlights a need for more research into manufacturer specific components," said Google.

 

Tags: Google , New Delhi , Sundar Pichai , Android Open Source Project , AOSP

 

 

related news

 

 

 

Photo Gallery

 

 

Video Gallery

 

 

5 Dariya News RNI Code: PUNMUL/2011/49000
© 2011-2024 | 5 Dariya News | All Rights Reserved
Powered by: CDS PVT LTD