Sci-tech

October 2019 Android Security Update Now Available for Pixel Devices

October 2019 Android Security Update Now Available for Pixel Devices”

Google's Android team has now released a patch for the vulnerability.

While it's unlikely average Android users will be targeted by whoever is exploiting the bug, it's severe enough that everyone should install the October 2019 security update once it's available on their specific device, and those using any of the smartphones listed above should take extra care in the meantime.

Kernel privilege escalation using a use-after-free vulnerability, accessible from inside the Chrome sandbox.

In simpler language, an attacker can install a malicious application on affected devices and achieve root without the user's knowledge, and as we all know, the road opens up completely after that. If this sounds serious to you, then that is because it certainly is - the vulnerability has been rated as "High Severity" on Android.

When delivered through a website, the vulnerability only needs to be paired with a renderer exploit to allow for full compromise of devices susceptible to it.

In addition to the functional patches, there are several patches for Pixel phones, including the common Android security patches.

More news: Former president Jimmy Carter receives stitches after fall

There's one thing worse than waiting for your phone to get a new version of Android, and that's a brand-new phone launching with an old version of the platform.

Currently, we are seeing new 10.0.0 files for Pixel 3a and Pixel 3a XL (QP1A.191005.007), Pixel 3 and Pixel 3 XL (QP1A.191005.007), Pixel 2 and Pixel 2 XL (QP1A.191005.007.A1), and Pixel and Pixel XL (QP1A.191005.007.A1). "Pixel 3 and 3a devices are not vulnerable while Pixel 1 and 2 devices will be receiving updates for this issue as part of the October update", Tim Willis, Project Zero member mentioned in a post.

The Project Zero research team has shared a local proof-of-concept exploit to demonstrate how this bug can be used to gain arbitrary kernel read/write when running locally.

Project Zero does not have samples of the exploit.

Stone said the bug was patched in December 2017, but Google's Pixel 2 and 2XL smartphones with the most recent security bulletin are still vulnerable to the flaw, a source code review found. Enter your email to be subscribed to our newsletter.



Like this

loading...
loading...

Latest


08 October 2019
Migrant Ship Sank near Lampedusa, there Are Casualties
A UNHCR spokesperson, Charlie Yaxley, told Reuters that more than 1,000 people have died in the Mediterranean in 2019, most on the route from Libya to Europe.

08 October 2019
Apple Might Include 96W Charging with the 16-inch MacBook Pro
As per the source of the publication, the charger supports four output gear positions- 5.2V-3A, 9V-3A, 15V-3A, and 20.5V-4.3A. It is expected, Apple will launch its 16-inch MacBook Pro with similar specs like the traditional 15-inch MacBook Pro.

08 October 2019
No-Deal Brexit Court Case: Theo Usherwood Explains The Verdict
Another EU officials insisted negotiations have never been conducted on the basis of offers and counter offers. But Brussels is likely to see the new text as not enough to change the bloc's position.

08 October 2019
U.S. signs limited deal with Japan on agriculture, digital trade
"This is a huge victory for America's farmers, ranchers and growers", Trump said in a signing ceremony at the White House . Trump has threatened to impose import taxes on foreign autos, claiming they pose a threat to U.S. national security.

08 October 2019
Instagram is removing its 'Following' activity tab
Instagram's head of product, Vishal Shah , says the decision was due to the fact that hardly anyone used the feature anyway. It's a feature on the Instagram app that's existed since 2011, allowing users to see what their friends are up to.

08 October 2019
Typhoon could leave Ireland on brink of World Cup elimination
But the rules now state that any games cancelled at the World Cup due to weather problems are registered as scoreless draws . Ireland's defence coach Andy Farrell said World Rugby is as "keen as we are to get this game played", the BBC reports.

08 October 2019
Alesha Dixon shares photo of baby girl
The singer opted to wear a black vest top, tucked in a a pair of khaki pants , as she enjoyed a stroll around Los Angeles. The smile on Alesha's face couldn't have been wider as she appeared to be relishing in becoming a mother-of-two.

08 October 2019
Nita Ambani to present match ball to National Basketball Association officials
The RF ESA has overall impacted 18 million children through sports initiatives in basketball, football and athletics. Indiana Pacers and Sacramento Kings will play two pre-season friendly games on Friday and Saturday at NSCIin Worli.

08 October 2019
Swedish royal children lost their titles overnight
The monarchy enjoys widespread support despite the egalitarianism that otherwise characterizes society in the Nordic country. If you include the next generation there are now ten people in the line of succession, ' Wersall said.

08 October 2019
Unilever to halve use of new plastic
It has also introduced detectable pigment in its black plastics for brands including Aex and TRESemme. We are also committed to ensuring all our plastic packaging is reusable, recyclable or compostable.