Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

Google Patches Remotely Exploitable Vulnerabilities in Android

Android May 2019 Patches Fix Critical Remote Code Execution Vulnerabilities

The May 2019 set of security patches released for the Android operating system address 8 Critical vulnerabilities, including 4 remote code execution flaws. 

Android May 2019 Patches Fix Critical Remote Code Execution Vulnerabilities

The May 2019 set of security patches released for the Android operating system address 8 Critical vulnerabilities, including 4 remote code execution flaws. 

The most severe of the resolved issues is a critical bug in Media framework that could be exploited remotely using a specially crafted file to execute arbitrary code within the context of a privileged process. 

Tracked as CVE-2019-2044, the vulnerability impacts Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9 and was addressed on all devices running the Android 2019-05-01 security patch level. 

Other Critical vulnerabilities addressed in this patch level include 3 remote code execution flaws in System (CVE-2019-2045, CVE-2019-2046, and CVE-2019-2047). The issues impact Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9. 

Five other vulnerabilities were addressed in System this month, including two elevation of privilege (CVE-2019-2049 and CVE-2019-2050) and three information disclosure (CVE-2019-2051, CVE-2019-2052, and CVE-2019-2053) flaws. All five are rated High severity.

The Android 2019-05-01 security patch level also fixes a Moderate risk elevation of privilege bug in Framework (CVE-2019-2043), Google explains in an advisory.

The second part of this month’s set of Android patches addresses issues in Kernel components, NVIDIA components, Broadcom components, Qualcomm components, and Qualcomm closed-source components. 

Advertisement. Scroll to continue reading.

Addressed on all devices running the Android 2019-05-05 security patch level, these flaws include a Moderate severity elevation of privilege bug in Kernel components, a High risk severity elevation of privilege issue in NVIDIA components, and a High risk remote code execution vulnerability in Broadcom components.

Two flaws addressed in Qualcomm components were rated High severity, while the 15 issues resolved in Qualcomm closed-source components included 4 Critical severity and 11 High risk bugs. 

The same as in the past several months, the Pixel Update Bulletin for May 2019 contains no security patches. No functional patches were released for these devices either.

However, Pixel devices will receive an update that will deliver fixes for the issues in the May 2019 Android Security Bulletin.

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Mobile & Wireless

Infonetics Research has shared excerpts from its Mobile Device Security Client Software market size and forecasts report, which tracks enterprise and consumer security client...

Mobile & Wireless

Samsung smartphone users warned about CVE-2023-21492, an ASLR bypass vulnerability exploited in the wild, likely by a spyware vendor.

Malware & Threats

Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down.

Fraud & Identity Theft

A team of researchers has demonstrated a new attack method that affects iPhone owners who use Apple Pay and Visa payment cards. The vulnerabilities...

Mobile & Wireless

Critical security flaws expose Samsung’s Exynos modems to “Internet-to-baseband remote code execution” attacks with no user interaction. Project Zero says an attacker only needs...

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Mobile & Wireless

Asus patched nine WiFi router security defects, including a highly critical 2018 vulnerability that exposes users to code execution attacks.