Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

40 Vulnerabilities Patched in Android With August 2023 Security Updates

40 vulnerabilities have been patched by Google in the Android operating system with the release of the August 2023 security updates.

Just over 40 vulnerabilities have been patched by Google in the Android operating system with the release of the August 2023 security updates. 

According to the tech giant, the most serious of the vulnerabilities is CVE-2023-21273, a critical remote code execution issue affecting the System component. No user interaction or elevated privileges are required for exploitation. CVE-2023-21273 impacts Android 11, 12, 12L and 13.

Several other vulnerabilities have also been rated ‘critical’, including CVE-2023-21282 (remote code execution flaw in Media Framework component), CVE-2023-21264 (kernel privilege escalation flaw), and CVE-2022-40510 (memory corruption in Qualcomm closed-source components). 

Three dozen of the security holes patched with the latest updates have been assigned a ‘high severity’ rating. A majority can lead to privilege escalation and information disclosure, and some can be exploited for denial-of-service (DoS) attacks. 

“Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform. We encourage all users to update to the latest version of Android where possible,” Google noted in its security bulletin.

Google also announced patches for a few vulnerabilities affecting Wear OS and Pixel phones. No fixes have been released for the Android Automotive OS.

Advertisement. Scroll to continue reading.

The tech giant also announced on Tuesday that the upcoming Android 14 will introduce new cellular security mitigations for consumers and enterprises. This includes the ability to disable 2G support, and a feature to disable support for null-ciphered cellular connectivity. 

Threat actors, particularly commercial spyware vendors, have exploited Android zero-days to achieve their goals. 

Google is aware of four Android vulnerabilities with 2023 CVE identifiers that have been exploited in attacks. However, the company noted recently that it can take so long for Android patches to reach end users that n-day vulnerabilities are often just as good as zero-days. 

Related: Android’s June 2023 Security Update Patches Exploited Arm GPU Vulnerability

Related: Android Security Update Patches Kernel Vulnerability Exploited by Spyware Vendor

Related: Google, CISA Warn of Android Flaw After Reports of Chinese App Zero-Day Exploitation 

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.