Critical Android Bugs — Samsung Fix Released

Home/Mobile Security, Security Update/Critical Android Bugs — Samsung Fix Released

Critical Android Bugs — Samsung Fix Released

Samsung started rolling out Android’s March 2021 security updates for critical security vulnerabilities.

March 2021 — Samsung Update

Though exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform.

Smartphones are regularly getting updates from their respected Android vendors.

As observed by BleepingComputer, Samsung Galaxy devices are automatically pulling updates released on March 5, 2021, this week.

Follow Us on: Twitter, InstagramFacebook to get the latest security news!

For critical Android bugs Samsung has started rolling out March 2021 security updates to mobile devices in the runtime, operating system, and related components.

Also, the updates mainly comprise security fixes for Samsung Galaxy built-in apps with couple of enhancements like

  • Calendar
  • Display
  • Social Platform
  • SmartThings.

The vulnerability CVE-2021-0395 could enable a local attacker to execute arbitrary code within the context of a privileged process.

CVEReferencesTypeSeverityUpdated AOSP versions
CVE-2021-0397A-174052148RCECritical8.1, 9, 10, 11

Android runtime

Here, the vulnerability in this section could enable a local attacker to execute arbitrary code within the context of a privileged process.

CVEReferencesTypeSeverityUpdated AOSP versions
CVE-2021-0395A-170315126EoPHigh11

Framework

Importantly, the most severe vulnerability in this section could enable a local attacker with privileged access to gain access to sensitive data.

CVEReferencesTypeSeverityUpdated AOSP versions
CVE-2021-0391A-172841550EoPHigh8.1, 9, 10, 11
CVE-2021-0398A-173516292EoPHigh11

System

On the other hand, the most severe vulnerability in this section could enable a remote attacker using a specially crafted transmission to execute arbitrary code within the context of a privileged process.

CVEReferencesTypeSeverityUpdated AOSP versions
CVE-2017-14491A-158221622RCEHigh8.1, 9, 10, 11
CVE-2021-0393A-168041375RCEHigh8.1, 9, 10, 11
CVE-2021-0396A-160610106RCEHigh8.1, 9, 10, 11
CVE-2021-0390A-174749461EoPHigh8.1, 9, 10, 11
CVE-2021-0392A-175124730EoPHigh9, 10, 11
CVE-2021-0394A-172655291 [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12]IDHigh8.1, 9, 10, 11

Google Play system updates

The following issues are included in Project Mainline components.

ComponentCVE
WiFiCVE-2021-0390

Security Recommendations:

Android users are advised to update their Android devices immediately and recommended to have the “auto-update” settings enabled to safeguard against these bugs

By | 2021-03-07T12:35:47+05:30 March 7th, 2021|Mobile Security, Security Update|

About the Author:

FirstHackersNews- Identifies Security

Leave A Comment

Subscribe to our newsletter to receive security tips everday!