This website uses cookies

Our website, platform and/or any sub domains use cookies to understand how you use our services, and to improve both your experience and our marketing relevance.

Manage client sites with AI. Join our free live webinar and see Cloudways MCP in action.Register now!

Google Fixes Critical Android Kernel Vulnerability Under Active Exploitation

Updated on August 6, 2024

< 1 Min Read
Google Duped into Advertising Malicious Authenticator Version

Google has patched a high-severity security flaw in the Android kernel, tracked as CVE-2024-36971, which has been actively exploited in the wild. This vulnerability, which enables remote code execution on the kernel, has been identified as potentially being targeted by commercial spyware vendors for narrowly focused attacks.

The company’s August 2024 security bulletin indicates that the flaw is currently under limited, targeted exploitation, though specific details about the cyber-attacks or the threat actors involved have not been disclosed. There is no information yet on whether Pixel devices are affected.

via GIPHY

Clement Lecigne from Google’s Threat Analysis Group (TAG) reported the vulnerability, which is part of a broader patch addressing 47 issues across various components, including those from Arm, Imagination Technologies, MediaTek, and Qualcomm. The update also resolves 12 privilege escalation flaws, one information disclosure bug, and one denial-of-service (DoS) flaw within the Android Framework.

In related news, Google previously disclosed an elevation of privilege issue in Pixel Firmware (CVE-2024-32896) that impacted not only Pixel devices but the broader Android ecosystem. The company has been collaborating with OEM partners to ensure widespread application of fixes.

Meanwhile, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included CVE-2018-0824, a remote code execution vulnerability in Microsoft COM for Windows, in its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies are required to apply fixes by August 26, 2024, following its exploitation by APT41, a Chinese state-sponsored group targeting a Taiwanese research institute.

This patch underscores the ongoing need for vigilance and timely updates to protect against evolving cyber threats.

Share your opinion in the comment section. COMMENT NOW

Share This Article

Abdul Rehman

Abdul is a tech-savvy, coffee-fueled, and creatively driven marketer who loves keeping up with the latest software updates and tech gadgets. He's also a skilled technical writer who can explain complex concepts simply for a broad audience. Abdul enjoys sharing his knowledge of the Cloud industry through user manuals, documentation, and blog posts.

×

Webinar: How to Get 100% Scores on Core Web Vitals

Join Joe Williams & Aleksandar Savkovic on 29th of March, 2021.

Do you like what you read?

Get the Latest Updates

Share Your Feedback

Please insert Content

Thank you for your feedback!

Do you like what you read?

Get the Latest Updates

Share Your Feedback

Please insert Content

Thank you for your feedback!

Want to Experience the Cloudways Platform in Its Full Glory?

Take a FREE guided tour of Cloudways and see for yourself how easily you can manage your server & apps on the leading cloud-hosting platform.

Start my tour