Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

Google Android Security Update Patches 40 Vulnerabilities

Google on Tuesday published the Android Security Bulletin for September 2021 with patches for a total of 40 vulnerabilities, including seven that are rated critical.

Google on Tuesday published the Android Security Bulletin for September 2021 with patches for a total of 40 vulnerabilities, including seven that are rated critical.

A total of 16 issues were patched with the first part of this month’s security updates – the 2021-09-01 security patch level – including one critical issue in the Framework component. Tracked as CVE-2021-0687, the security bug affects Android 8.1, 9, 10, and 11.

“The most severe of these issues is a critical security vulnerability in the Framework component that could enable a remote attacker using a specially crafted file to cause a permanent denial of service,” according to Google’s advisory.

Six other vulnerabilities were patched in the Framework component, all considered high-severity. These include five elevation of privilege flaws and one information disclosure vulnerability.

Google also released patches for two high severity information disclosure issues in Media framework, and seven vulnerabilities in the System component: six high severity (two elevation of privilege and four information disclosure bugs) and one medium severity (elevation of privilege).

[ READ: Microsoft Office Zero-Day Hit in Targeted Attacks ]

Advertisement. Scroll to continue reading.

This month’s Android patches also include a Google Play system update to address the CVE-2021-0690 vulnerability.

The second part of September 2021’s set of patches arrives on devices as the 2021-09-05 security patch level and includes fixes for a total of 23 vulnerabilities in Kernel components, MediaTek components, Unisoc components, Qualcomm components, and Qualcomm closed-source components.

Seven of these security holes, all of them addressed in Qualcomm closed-source components, are rated critical.

Google also announced patches Pixel devices address a total of nine other vulnerabilities, in Kernel, Pixel components, Qualcomm components, and Qualcomm closed-source components.

Pixel devices running a security patch level of 2021-09-05 or later have been patched for all of these issues, as well as for the vulnerabilities in the September 2021 Android Security Bulletin.

Related: Google Patches High-Risk Android Security Flaws

Related: Google Details New Privacy and Security Policies for Android Apps

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

John Opala has joined Ralph Lauren as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.