Android security updates: 7 critical vulnerabilities fixed

Google releases its monthly update for its Nexus users; which eliminated some severe security vulnerabilities in its Android OS. The latest update patches a bug which can be exploited by an MMS, Email or a website which contains a specially crafted media file.

These patched flaws are effecting Android KitKat 4.4.4,  Android Lollipop 5.1 and Android 6.0 versions. Two critical remote execution vulnerabilities in media server could allow an attacker to cause memory corruption and remote code execution as the media server process.

The patched bugs are reported on January 4th this year. Blackberry was the only vendor who released an update for its PRIV handsets, within few hours of Google’s OTA update for Nexus users. Samsung users will have to wait for a week or two before they update their Android handsets.

The critical flaws which are fixed in Nexus devices are:

  • Remote Code Execution Vulnerability in Broadcom Wi-Fi Driver
  • Remote Code Execution Vulnerability in Mediaserver
  • Elevation of Privilege Vulnerability in Qualcomm Performance Module
  • Elevation of Privilege Vulnerability in Qualcomm Wi-Fi Driver
  • Elevation of Privilege Vulnerability in the Debugger Daemon 
This is the seventh update Google has released since the start of its monthly security update program in June last year. Android security researchers earned around $200,000 since the program is launched. 
Ehacking Staff
With more than 50 global partners, we are proud to count the world’s leading cybersecurity training provider. EH Academy is the brainchild of Ehacking, which has been involved in the field of training since the past Five years and continues to help in creating professional IT experts.

Most Popular

Blind SQL Injection Tutorial to Hack a Website

In the previous article, we have the basics of SQL Injection; what SQLi is and what are the types of SQL injection. And, In...

What is SQL Injection? Tutorial: Type and Example

What is SQL injection, and what are the types of SQL injection? These are the common questions, and we will seek the answer to...

Are Cisco 300-410 Exam and Its Related Certification Your Pathway to Career Success? Find Out about This

Introduction Career success can mean different things to different people. For some, it could mean having a prestigious title and for others, it could be...

How to Hack Windows 10 Password Using FakeLogonScreen in Kali Linux

This article demonstrates an in-depth guide on how to hack Windows 10 Passwords using FakeLogonScreen. Hacking Windows 10 password is an exciting topic and...

LOOKING FOR HACKING RECIPES FORM THE PRO?

Then sign up for FREE to the ehacking’s exclusive group. You will get the exclusive tips/tricks, tutorials, webinars & courses that I ONLY share with my fellow on this exclusive newsletter.