CERT-In Warns of Over 50 Security Flaws Affecting Android Smartphones: All You Need to Know

CERT-In, or Computer Emergency Response Team of India, has warned of multiple security vulnerabilities affecting multiple Android versions. If exploited by malicious users, these security vulnerabilities can be used to execute dangerous code, collect sensitive data, and launch denial of service (DoS) attacks on victims. According to the cybersecurity agency, the security vulnerabilities affect three major versions of Android and cover every part of Google’s operating system (OS) – from frameworks to components from Arm, MediaTek, Qualcomm, Unisoc and others.

In a vulnerability note released earlier this week, CERT-In listed 51 security vulnerabilities affecting the Android operating system. The nodal agency responsible for addressing cybersecurity issues and threats has issued a critical severity rating for the vulnerability description. All entries listed by CERT-In have been assigned a Common Vulnerabilities and Exposures (CVE) number.

According to CERT-In, the vulnerabilities affect Android 13, Android 12, Android 12L, and Android 11. It’s unclear whether Android 14 is also affected, as the source code for Android 14 was released days before the advisory.

The 51 security vulnerabilities listed by CERT-In affect various parts of the Android operating system, ranging from the Android framework, Android system, and Google Play system updates. At the same time, component software not directly controlled by Google, including components from Arm, MediaTek, Unisoc, and Qualcomm, are also affected by these vulnerabilities.

According to CERT-In, an attacker who exploits these flaws could escalate privileges on a target smartphone, execute arbitrary (malicious) code, extract sensitive information, or even perform a denial of service (DoS) attack.

Two of the flaws – CVE-2023-4863 and CVE-2023-4211 The agency said it could be actively exploited by attackers and users should apply security patches “urgently”. The flaws are related to the Chromium engine that powers Google Chrome and GPU memory processing operations on Android.

Users running on Pixel smartphones can install the latest update, which includes October security patch. Unfortunately, users with smartphones from other manufacturers will have to wait for security updates and fixes for these security flaws to be released.


Affiliate links may be generated automatically – see our Ethics Statement for details.

Svlook

Leave a Reply

Your email address will not be published. Required fields are marked *