Android Security Update  - 9ewjq1554294975 - Android Security Update released with the fixes for 2 RCE Vulnerabilities

Android bulletin published new updates with the fixes for critical vulnerabilities that affected Android devices.

Patched vulnerabilities Include 2 remote code execution vulnerabilities let hackers execute the code remotely to control the vulnerable Android devices, also these  two critical vulnerabilities impact all Android 7.0 or later devices.

patched totally 11 vulnerabilities that include, two remote code execution affected the media framework under “critical” severity and 9 “high” severity vulnerabilities that exist in system and Framework.

CVE-2019-2027 and CVE-2019-2028, Two remote code execution vulnerabilities enable a remote attacker to execute arbitrary code using a specially crafted file within the context of a privileged process.

CVE-2019-20, A high severity vulnerability affected Android Framework let the local attacker gain additional permissions bypass with user interaction.

Remaining 8 other system level high severity vulnerabilities, enable a local malicious application to execute arbitrary code within the context of a privileged process.

Remaining 8 other system level high severity vulnerabilities, enable a local malicious application to execute arbitrary code within the context of a privileged process.

Android Security Update

Media Framework

CVE References Type Severity Updated AOSP versions
CVE-2019-2027 A-11912061 RCE Critical 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2019-2028 A-120644655 RCE Critical 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9

Framework

CVE References Type Severity Updated AOSP versions
CVE-2019-2026 A-120866126 EoP High 8.0

System

CVE References Type Severity Updated AOSP versions
CVE-2019-2030 A-119496789 EoP High 9
CVE-2019-2031 A-120502559 EoP High 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2019-2033 A-121327565 EoP High 9
CVE-2019-2034 A-122035770 EoP High 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2019-2035 A-122320256 EoP High 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2019-2038 A-121259048 ID High 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2019-2039 A-121260197 ID High 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2019-2040 A-122316913 ID High 9

All the Android users are requested to update your phone immediately to apply the latest Android security patch.

To how to check a device’s security patch level, see Check and update your Android version.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

Most Important Android Penetration Testing Tools for Hackers & Security Professionals





Source link

No tags for this post.

LEAVE A REPLY

Please enter your comment!
Please enter your name here