Three security vulnerabilities found on MediaTek and Qualcomm chipsets were finally patched late last year after leaving 66% of Android phones at risk.
A trio of vulnerabilities discovered in Qualcomm and MediaTek chipsets were finally patched late last year, but not before two-thirds of Android handsets were at the risk of having an attacker gain access to media and audio conversations. Both Qualcomm and MediaTek employ the Apple Lossless Audio Codec which allows for lossless data compression of digital music streams.
Just over a decade ago, Apple made ALAC open-source allowing the format to be used on non-Apple devices including Android phones. There have been several updates but it had not been patched since 2011.discovered that attackers could use the vulnerabilities to execute a remote code execution attack.
Check Point passed the information it had gathered to both Qualcomm and MediaTek. The latter"awarded" two Common Vulnerabilities and Exposures vulnerability numbers, CVE-2021-0674 and CVE-2021-0675, to the ALAC vulnerabilities which had already been fixed by MediaTek and published in the December 2021 MediaTek Security Bulletin. Qualcomm released a patch for CVE-2021-30351 in the December 2021 Qualcomm Security Bulletin.
Security researcher Slava Makkaveev, who discovered the vulnerabilities along with Netanel Ben Simon, said,"The vulnerabilities were easily exploitable. A threat actor could have sent a song and when played by a potential victim, it could have injected code in the privileged media service. The threat actor could have seen what the mobile phone user sees on their phone.
Australia Latest News, Australia Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
Three sailors from same aircraft carrier found dead within a weekThree sailors assigned to the USS George Washington aircraft carrier were found dead within less than a week, prompting an investigation from the Navy and local authorities.
Read more »
Gartner Says Three Emerging Environmental Sustainability Technologies Will See Early Mainstream Adoption by 2025.Gartner_IT says 3 emerging environmental sustainability technologies will see early mainstream adoption by 2025: cloud sustainability, carbon footprint measurement & advanced grid management software. Read more here. GartnerTGI EarthDay2022
Read more »
Bitcoin Eyes 200-Day Average After Three-Day Price Rally, Analyst SaysBitcoin technical charts point to a continued rally toward the 200-day average resistance at $48,000. reports godbole17
Read more »
Bitcoin hovers around $41,000 on three-day riseBitcoin has had a positive week so far, trading above $41,000.
Read more »
Three sentenced for roles in nationwide card-skimming schemeThree men who pleaded guilty to federal charges for their roles in a years-long card skimming scheme that took financial information from people using ATMs and gas pumps in San Diego and elsewhere were sentenced Wednesday to prison terms.
Read more »
ESPN proposes three Seahawks Draft Day trades, but are they any good?Some mock drafts are fun; like really, really fun. And some mock drafts are dumb; like really, really dumb. Today’s article is about one of the really, really fun ones. Bill Barnwell’s All Trades...
Read more »