Google fixes dangerous rooting vulnerabilities in Android

Media processing and kernel privilege escalation flaws were patched in the January Android security update

Google has fixed a new batch of vulnerabilities in Android that could allow hackers to take over devices remotely or through malicious applications.

The company released over-the-air firmware updates for its Nexus devices Monday and will publish the patches to the Android Open Source Project (AOSP) repository by Wednesday. Manufacturers that are Google partners received the fixes in advance on Dec. 7, and will release updates according to their own schedules.

The new patches address six critical, two high and five moderate vulnerabilities. The most serious flaw is located in the mediaserver Android component, a core part of the operating system that handles media playback and corresponding file metadata parsing.

By exploiting this vulnerability attackers can execute arbitrary code as the mediaserver process, gaining privileges that regular third-party applications are not supposed to have. The vulnerability is particularly dangerous because it can be exploited remotely by tricking users into opening specifically crafted media files in their browsers or by sending such files via multimedia messages (MMS).

Google has been busy finding and patching media-file related vulnerabilities in Android since July, when a critical flaw in a media parsing library called Stagefright led to a major coordinated patching effort from Android device manufacturers and prompted Google, Samsung and LG to introduce monthly security updates.

It seems that the stream of media processing flaws is slowing down. The remaining five critical vulnerabilities fixed in this release stem from bugs in kernel drivers or the kernel itself. The kernel is the highest privileged part of the operating system.

One of the flaws was in the misc-sd driver from MediaTek and another in a driver from Imagination Technologies. Both could be exploited by a malicious application to execute rogue code inside the kernel, leading to a full system compromise that might require re-flashing the operating system in order to recover.

A similar flaw was found and patched directly in the kernel and two others were found in the Widevine QSEE TrustZone application, potentially allowing attackers to execute rogue code in the TrustZone context. TrustZone is a hardware-based security extension of the ARM CPU architecture that allows sensitive code to be executed in a privileged environment that's separate from the operating system.

Kernel privilege escalation vulnerabilities are the type of flaws that can be used to root Android devices -- a procedure through which users gain full control of their devices. While this capability is used legitimately by some enthusiasts and power users, it can also lead to persistent device compromises in the hands of attackers.

That's why Google does not allow rooting apps in the Google Play store. Local Android security features such as Verify Apps and SafetyNet are designed to monitor for and block such applications.

To make the remote exploitation of media parsing flaws harder, the automatic display of multimedia messages has been disabled in Google Hangouts and the default Messenger app since the first Stagefright vulnerability in July.

Join the CSO newsletter!

Error: Please check your email address.

More about ARMGoogleImagination TechnologiesLGMessengerSamsung

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Lucian Constantin

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts

Market Place