Google has patched 62 vulnerabilities in Android, including two zero-days that are actively being exploited in attacks, tracked as CVE-2024-53197 and CVE-2024-53150.
CVE-2024-53197 is a privilege escalation flaw found in the USB audio sub-component of the Linux Kernel. Local attackers are able to exploit the bug to access sensitive information on devices without any user interaction.
It does not yet have a CVSS rating, but according to researchers at Malwarebytes Labs, this was the link between two other vulnerabilities — CVE-2024-50302 and CVE-2024-53104 — which enabled law enforcement in Serbia to unlock a student activist’s device using Cellebrite forensic tools, before attempting to install spyware.
Puck och jag önskar alla en Glad Påsk!
Det är skärtorsdag, en del jobbar halvdag, dagen för helgdag (långfredag)...