​Android security: Google details Pixel and Nexus vulnerabilities in December bulletin

Google’s December security bulletin for Pixel and Nexus smartphones lists 42 vulnerabilities that are to be patched in an update.
More security news
NSA employee pleads guilty after stolen classified data landed in Russian hands

Security warning: Don’t use Russian antivirus on secret government systems, says cyber-agency
Security: Making yourself a hard target for hackers is easier than you think
Forgotten password? Samsung’s future phones could retrieve it using your palm
“All supported Google devices will receive an update to the 2017-12-05 patch level. We encourage all customers to accept these updates to their devices,” Google said.
网络安全公益短片防范社工电话诈骗
These vulnerabilities are in addition to the bugs listed in Google’s December 2017 Android security bulletin. Google notes that its hardware partners were notified of these issues at least a month ago “and may choose to incorporate them as part of their device updates”.
Of the Nexus and Pixel-specific bugs, five are listed in the media framework, varying between high and moderate criticality, and featuring elevation of privilege and information disclosure risks.
There is one bug in Broadcom components that’s also related to elevation of privilege, nine kernel bugs that involve elevation of privilege and information disclosure (one is high, the rest are moderate), plus one MediaTek-related flaw.
There are also 26 Qualcomm bugs (all moderate) plus four more in closed-source components — three moderate and one critical.
Google’s Android security bulletin for December warns of 47 bugs: 10 of the vulnerabilities are rated ‘critical’ in their potential impact — the most severe type of bugs; the other 37 are rated as ‘high’ priority.Previous and related coverage Android’s big problem: Over a billion devices are more than two years out of date
Android’s rapid growth and update challenges have left over one billion devices running very out of date software.
Android security triple-whammy: New attack combines phishing, malware, and data theft
Attacks on three fronts ensure attackers have all the information they need to steal banking details in the latest evolution of the Marcher malware, warn researchers.
要让分布于全国(全球)各地区的员工们及时轻松地了解到最新的安全威胁,和掌握基本的安全应对措施,您需要“云”端培训系统。
Google says these are the best Android apps of 2017 but do you agree?
Google names most popular and best Android apps of the year.Read more on Android security Google names 42 Android devices with users running security updates from last two monthsAndroid Oreo: Google adds in more Linux kernel security featuresGoogle Play Protect rolling out to Android devices for better securityAmazon’s app store compromises Android securityMost Android users running outdated security patches: report (CNET)iOS and Android security: A timeline of the highlights and the lowlights (TechRepublic)
Related Topics:
Google
Security TV
Data Management
涉密网络通常与互联网进行了物理隔绝,针对涉密网络的攻击需要跳板,技术上得注意U盘,手机等移动设备接入涉密网络,更重要的是加强人员的安全意识教育。

猜您喜欢

公司与员工之间的新纽带——在线培训沟通平台
互联网金融移动APP与虚假WIFI的信息安全教训
网络安全法宣传片 002 国家网络安全的现状与重要性概述
36岁余文乐发结婚照 和王棠云墨尔本低调完婚
24-7 BOIZMODELS
互联网安全宣传——识别和应对社会工程学诈骗