-
CVE-2025-0096 – Fix malloc buffer size (6th Feb 2025)
Original release date: February 3, 2025 Preface: The Hardware Abstraction Layer (HAL) is not outdated with Android 15. In fact, HAL continues to play a crucial role in the Android architecture. Android 15 includes improvements and updates to various HAL components, ensuring they remain relevant and effective for modern hardware and software requirements. Background: Android…
-
CVE-2025-0098 : Prevent activity token leaked to another process (3rd Feb 2025)
Preface: Android frameworks deliver an environment where you already have access to libraries, best practices, and extensive help documentation. As a matter of fact, there are well over ten android frameworks. Background: TaskFragmentOrganizerController[.]java is a part of the Android Open Source Project (AOSP). It is located in the services/core/java/com/android/server/wm directory of the Android framework. This…
-
CVE-2024-11863, CVE-2024-11864 and CVE-2024-9413: Three different CVEs were discovered that expose the System Control Processor (SCP) to attack threats. (16th Jan 2025)
Preface: SCMI is a message driven interface between an SCMI agent (client) and an SCMI host (server) Background: SCP Firmware provides a software reference implementation for the System Control Processor (SCP) and Manageability Control Processor (MCP) components found in several Arm Compute Sub-Systems. Power Control System Architecture (PCSA) defines the concept of a System Control…
-
CVE-2024-43704: improper GPU system calls to gain access to the graphics buffers of a parent process. (10th Jan 2025)
Preface: PowerVR is a division of Imagination Technologies (formerly VideoLogic) that develops hardware and software for 2D and 3D rendering, and for video encoding, decoding, associated image processing and DirectX, OpenGL ES, OpenVG, and OpenCL acceleration. Background: Imagination maintains DDKs for Android, Linux and Windows operating systems, ensuring they have access to the latest APIs and popular extensions. To…
-
CVE-2024-20154: Stack overflow in Modem (9th Jan 2024)
Preface: Vulnerability findings appear to have changed compared to five years ago. As a matter of fact, the trend of open source concept driven the a lot of details visible, a bunch of vulnerabilities have accumulated in 2024, and the Android security advisory on January 2025 shows you what’s the actual status. Manufacturers will have…
-
CVE-2024-21464 – msm: ipa3: adding a preventive check for holb stats (8th JAN 2025)
Preface: Vulnerability findings appear to have changed compared to five years ago. As a matter of fact, the trend of open source concept driven the a lot of details visible, a bunch of vulnerabilities have accumulated in 2024, and the Android security advisory on January 2025 shows you what’s the actual status. Manufacturers will have…
-
An Android security bulletin was published on January 6, 2025, which disclosed multiple vulnerabilities but did not provide details (7th Jan 2025)
Preface: Vulnerability findings appear to have changed compared to five years ago. As a matter of fact, the trend of open source concept driven the a lot of details visible, a bunch of vulnerabilities have accumulated in 2024, and the Android security advisory on January 2025 shows you what’s the actual status. Manufacturers will have…
-
CVE-2024-33063 – OOB : read/writes in ML probe generation (15-Dec 2024)
Preface: A patch published June 2023, adds parsing of the data and adding/updating the BSS using the received elements. Doing this means that userspace can discover the BSSes using an ML probe request and request association on these links. Background: IE provides information on channel usage by AP, so that smart wireless stations can decide…
-
CVE-2024-38424 Use After Free in GPS (14-12-2024)
Preface: There are four global satellite navigation systems, currently GPS (United States), GLONASS (Russian Federation), Beidou (China) and Galileo (European Union). Background: Android Opensource is called HLOS. Qualcomm’s proprietary one is called non-HLOS. The Android on Snapdragon architecture is built to allow for common feature adoption across devices with Snapdragon. It represents the software features…
-
CVE-2024-38403 – Buffer Over-read in WLAN Firmware (8th Nov 2024)
Preface: BSS Transition Management enables an AP to request a voice client to transition to a specific AP, or suggest a set of preferred APs to a voice client, due to network load balancing or BSS termination. Background: A STA receiving a BSS Transition Management Request frame may respond with a BSS Transition Management Response…