CIP Cyber

Android security updates: 7 critical vulnerabilities fixed

Table of Contents

Google releases its monthly update for its Nexus users; which eliminated some severe security vulnerabilities in its Android OS. The latest update patches a bug which can be exploited by an MMS, Email or a website which contains a specially crafted media file.

These patched flaws are effecting Android KitKat 4.4.4,  Android Lollipop 5.1 and Android 6.0 versions. Two critical remote execution vulnerabilities in media server could allow an attacker to cause memory corruption and remote code execution as the media server process.

The patched bugs are reported on January 4th this year. Blackberry was the only vendor who released an update for its PRIV handsets, within few hours of Google’s OTA update for Nexus users. Samsung users will have to wait for a week or two before they update their Android handsets.

The critical flaws which are fixed in Nexus devices are:

  • Remote Code Execution Vulnerability in Broadcom Wi-Fi Driver
  • Remote Code Execution Vulnerability in Mediaserver
  • Elevation of Privilege Vulnerability in Qualcomm Performance Module
  • Elevation of Privilege Vulnerability in Qualcomm Wi-Fi Driver
  • Elevation of Privilege Vulnerability in the Debugger Daemon 
This is the seventh update Google has released since the start of its monthly security update program in June last year. Android security researchers earned around $200,000 since the program is launched. 
CIP Cyber Staff

CIP Cyber Staff

CIP Cyber Staff comprises CIP cybersecurity experts committed to delivering comprehensive information on critical infrastructure protection. The content covers diverse topics, equipping professionals to defend organizations and communities in an ever-evolving cyber landscape.

Most popular

Industrial Cybersecurity

Want always be up to date?

Don't miss the latest news

By subscribing to our mailing list, you will be enrolled to receive our new trainings, latest blog posts, product news, and more.

CIP Training & Certifications

Transform your cybersecurity skills with CIP Cyber’s comprehensive training & course offerings

Related Articles

Want always be up to date?

Don't miss the latest news

By subscribing to our mailing list, you will be enrolled to receive our new trainings, latest blog posts, product news, and more.

CIP Training & Certifications

Transform your cybersecurity skills with CIP Cyber’s comprehensive training & course offerings