HT TECH wants to start sending you push notifications. Click allow to subscribe

Google researchers discover critical Android security flaw; Pixel, Samsung, Huawei, Xiaomi phones affected

Huawei P20, Xiaomi Mi A1, and Google’s own Pixel 2 are some of the phones affected by the newly discovered security flaw.

By: KUL BHUSHAN
Updated on: Aug 20 2022, 17:09 IST
Google researchers discover critical Android flaw affecting Pixel, Samsung and Huawei phones (Reuters)

Google's Project Zero researchers have discovered a critical security flaw in its own Android that affected some popular smartphones across brands. Researchers claim the "zero-day" flaw was exploited in the real-world by Israel's NSO Group, known for the Pegasus interception software.

The flaw affected Google's recent Android 8.x and above versions. Interestingly enough, the bug was fixed in earlier iterations of Android (3.18, 4.4, 4.9) but resurfaced again.

You may be interested in

Mobiles Tablets Laptops
11% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹119,999₹134,999
Buy now
38% OFF
Google Pixel 7 Pro 5G
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹61,990₹99,999
Buy now
7% OFF
Google Pixel 7 5G
  • Obsidian
  • 8 GB RAM
  • 128 GB Storage
₹40,990₹43,999
Buy now
17% OFF
Xiaomi Redmi Note 13 Pro
  • Arctic White
  • 8 GB RAM
  • 128 GB Storage
₹24,950₹29,999
Buy now
24% OFF
Samsung Galaxy Book 3 Pro Intel Evo NP940XFG KC5IN Laptop
  • Graphite Beige
  • 16 GB RAM
  • 1 TB SSD
₹132,990₹173,990
Buy now
31% OFF
Samsung Galaxy Book 2 360 13 3 Laptop
  • Graphite
  • 16 GB DDR4 RAM
  • 512 GB SSD
₹83,691₹121,352
Buy now
26% OFF
Huawei MateBook X Pro Mach W19B Signature Edition Ultrabook
  • Mystic Silver
  • 8 GB RAM
  • 256 GB SSD
₹62,519₹84,990
Buy now
32% OFF
Xiaomi Mi Notebook 14 IC Laptop
  • Silver
  • 8 GB RAM
  • 256 GB SSD
₹40,990₹59,990
Buy now
15% OFF
Samsung Galaxy Tab S9 FE Plus 256GB
  • Silver
  • 12 GB RAM
  • 256 GB Storage
₹55,999₹65,999
Buy now
30% OFF
Samsung Galaxy Tab A9 Plus 5G 128GB
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹22,999₹32,999
Buy now
19% OFF
Samsung Galaxy Tab A9 Plus 64GB
  • Silver
  • 4 GB RAM
  • 64 GB Storage
₹18,649₹22,999
Buy now
25% OFF
Samsung Galaxy Tab A9 LTE
  • Silver
  • 4 GB RAM
  • 64 GB Storage
₹15,070₹19,999
Buy now

According to Google researchers, the Android vulnerability affects the following phones: Samsung S7, Samsung S8 and Samsung 9, LG Oreo, Moto Z3, Oppo A3, Xiaomi Mi A1, Xiaomi Redmi Note 5 and Xiaomi Redmi 5A, Huawei P20, and Google's own Pixel 2 with Android 9 and Android 10.

Also read: Looking for a smartphone? To check mobile finder click here.

ALSO READ: YouTube creators hit by massive wave of account hijacks

Researchers also pointed out that while the security flaw was quite critical, it wasn't as dangerous as the other zero-day exploits.

"This issue is rated as High severity on Android and by itself requires installation of a malicious application for potential exploitation. Any other vectors, such as via web browser, require chaining with an additional exploit," an Android spokesperson explained on the official forum.

"We have notified Android partners and the patch is available on the Android Common Kernel. Pixel 3 and 3a devices are not vulnerable while Pixel 1 and 2 devices will be receiving updates for this issue as part of the October update."

Saket Modi, CEO & Co-founder, Lucideus said that even though the vulnerability is severe and could be used to get root access to an Android device, users shouldn't need to be worried. He also recommended that users should avoid downloading apps from third-party app stores.

"Android Kernel 'mobile station modem (MSM)' is vulnerable to Use After Free vulnerability. This is a memory corruption gap that can be used to execute on arbitrary code or crash a cell phone. This Use After Free scenario can occur when "the memory in question is allocated to another pointer validly at some point after it has been freed. The original pointer to the freed memory is used again and points to somewhere within the new allocation. As the data is changed, it corrupts the validly used memory; this induces undefined behaviour in the process which an attacker can take advantage further getting a root access to the device," he explained.

"A similar kind of vulnerability was identified with Microsoft and its Internet Explorer web browser since 2013, which has since received numerous security patches to update a variety of Use-After-Free security vulnerabilities," he added.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 04 Oct, 17:42 IST

Sale

Mobiles Tablets Laptops
33% OFF
Samsung Galaxy S21 FE 2023
  • White
  • 8 GB RAM
  • 256 GB Storage
₹33,490₹49,999
Buy now
40% OFF
Samsung Galaxy A23
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹17,499₹28,990
Buy now
16% OFF
Samsung Galaxy A25 5G
  • Blue
  • 8 GB RAM
  • 128 GB Storage
₹23,999₹28,499
Buy now
54% OFF
Samsung Galaxy S22
  • Green
  • 8 GB RAM
  • 128 GB Storage
₹39,200₹85,999
Buy now
19% OFF
Samsung Galaxy Tab S6 Lite 2022
  • Chiffon Pink
  • 4 GB RAM
  • 64 GB Storage
₹24,999₹30,999
Buy now
13% OFF
Samsung Galaxy Tab A9
  • Silver
  • 4 GB RAM
  • 64 GB Storage
₹12,999₹14,999
Buy now
10% OFF
Samsung Galaxy Tab S9 Ultra 512GB
  • Beige
  • 12 GB RAM
  • 512 GB Storage
₹119,999₹133,999
Buy now
13% OFF
Samsung Galaxy Tab A9 LTE
  • Silver
  • 4 GB RAM
  • 64 GB Storage
₹12,999₹14,999
Buy now
28% OFF
MSI Summit E16 Flip A13VET 068IN Laptop
  • Ink Black
  • 32 GB RAM
  • 1 TB SSD
₹119,990₹165,990
Buy now
39% OFF
HP ZBook Firefly 14 G9 7M3T2PA Laptop
  • Nouvelle Silver
  • 16 GB RAM
  • 1 TB SSD
₹98,900₹162,500
Buy now
31% OFF
Asus TUF Gaming F17 FX706HC HX070T Laptop
  • Graphite Black
  • 8 GB RAM
  • 1 TB SSD
₹52,555₹75,990
Buy now
31% OFF
Asus Zenbook 14 Flip OLED UP3404VA KN753WS Laptop
  • Foggy Silver
  • 16 GB RAM
  • 1 TB SSD
₹67,990₹98,990
Buy now