Attackers exploit 0-day vulnerability that gives full control of Android phones

Peter Reutemann <[email protected]> Mon, 7 Oct 2019 11:55:55 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12+V+aQEZ+1k0fyrTu7LbZegsXtVexsC0AB09JcN5UK5bg@mail.gmail.com>
'Attackers are exploiting a zero-day vulnerability in Google’s Android
mobile operating system that can give them full control of at least 18
different phone models, including four different Pixel models, a
member of Google’s Project Zero research group said on Thursday night.

There’s evidence the vulnerability is being actively exploited, either
by exploit developer NSO Group or one of its customers, Project Zero
member Maddie Stone said in a post. NSO representatives, meanwhile,
said the "exploit has nothing to do with NSO." Exploits require little
or no customization to fully root vulnerable phones. The vulnerability
can be exploited two ways: (1) when a target installs an untrusted app
or (2) for online attacks, by combining the exploit with a second
exploit targeting a vulnerability in code the Chrome browser uses to
render content.

“The bug is a local privilege escalation vulnerability that allows for
a full compromise of a vulnerable device,” Stone wrote. “If the
exploit is delivered via the Web, it only needs to be paired with a
renderer exploit, as this vulnerability is accessible through the
sandbox.”'

-- source: https://arstechnica.com/information-technology/2019/10/attackers-exploit-0day-vulnerability-that-gives-full-control-of-android-phones/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz