Android security updates: 7 critical vulnerabilities fixed

Google releases its monthly update for its Nexus users; which eliminated some severe security vulnerabilities in its Android OS. The latest update patches a bug which can be exploited by an MMS, Email or a website which contains a specially crafted media file.

These patched flaws are effecting Android KitKat 4.4.4,  Android Lollipop 5.1 and Android 6.0 versions. Two critical remote execution vulnerabilities in media server could allow an attacker to cause memory corruption and remote code execution as the media server process.

The patched bugs are reported on January 4th this year. Blackberry was the only vendor who released an update for its PRIV handsets, within few hours of Google’s OTA update for Nexus users. Samsung users will have to wait for a week or two before they update their Android handsets.

The critical flaws which are fixed in Nexus devices are:

  • Remote Code Execution Vulnerability in Broadcom Wi-Fi Driver
  • Remote Code Execution Vulnerability in Mediaserver
  • Elevation of Privilege Vulnerability in Qualcomm Performance Module
  • Elevation of Privilege Vulnerability in Qualcomm Wi-Fi Driver
  • Elevation of Privilege Vulnerability in the Debugger Daemon 
This is the seventh update Google has released since the start of its monthly security update program in June last year. Android security researchers earned around $200,000 since the program is launched. 
Ehacking Staff
With more than 50 global partners, we are proud to count the world’s leading cybersecurity training provider. EH Academy is the brainchild of Ehacking, which has been involved in the field of training since the past Five years and continues to help in creating professional IT experts.

Most Popular

Improving WordPress Security in 2021

What Is WordPress? WordPress is a PHP-based content management system that may be used in conjunction with MySQL. The best part about WordPress is that...

OSINT Tutorial to Discover Antivirus of the Target

This OSINT tutorial demonstrates the "RECON-NG tool" on Kali Linux. It discovers the type of Anti-Virus software (AV) the victim is running on their...

Cracking Password Protected ZIP, RAR & PDF using Zydra

Having confidential documents on a system, like a pdf of financial data or a zip including personal images and videos, ensure they're password-protected so...

Four Ways SASE is Revolutionizing Network Security 

Are you interested in a network that offers amazing security features without compromising high-speed performance? With SASE, you don't have to settle for less....