As the world descends into madness, it's good to see some things never change: Monthly Android patches
- Reference: 1596572141
- News link: https://www.theregister.co.uk/2020/08/04/android_august_patches/
- Source link:
This [1]month's fixes include one remote-code-execution bug (CVE-2020-0240), present in the Android Framework. Google warns that the bug "could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process," though isn't being exploited... yet.
That flaw was the only remote-code-execution bug present in the 01 level of the security patch bundle. This is the most basic version of Android updates, only addressing the core components of the OS.
Elevation-of-privilege flaws were the most common issue elsewhere this month. Three such vulnerabilities were patched in the Media Framework (CVE-2020-0241, CVE-2020-0242, CVE-2020-0243), two in the Android System files (CVE-2020-0108, CVE-2020-0256) and two in Framework (CVE-2020-0238, CVE-2020-0257). These can be used by rogue apps to commandeer more of the device.
Also earning the "high" risk designation in the Android Framework were a trio of information-disclosure flaws (CVE-2020-0239, CVE-2020-0249, CVE-2020-0258) and a denial-of-service condition (CVE-2020-0247). A pair of information-leaking flaws were also patched in the Android System files (CVE-2020-0248, CVE-2020-0250). This is all minor stuff but could prove more serious if chained to other flaws.
Is it Patch Blues-day for Outlook? Microsoft's email client breaks worldwide, leaves everyone stumped [2]READ MORE
Those who have phones or tablets that use Qualcomm components (aka, most of us) will also get the 05 level fixes for six other vulnerabilities, all considered critical. Of these, five (CVE-2019-10562, CVE-2019-10615, CVE-2019-13998, CVE-2020-3619, CVE-2020-3667) are in closed-source components and therefore not detailed by Google, though the critical designation usually means remote code execution.
The other critical bug, CVE-2020-11116, is a buffer overflow in the Qualcomm WLAN component for Android gear. It is one of four CVE-listed vulnerabilities in WLAN this month, the other three (CVE-2020-11115, CVE-2020-11118, CVE-2020-11120) all being classified as high security risks. That suggests CVE-2020-11116 could be exploited over a wireless network to achieve code execution on a victim's device.
Qualcomm's closed-source gear was by far the most-patched part of Android this month. In addition to those five critical patches, another 22 CVE-listed vulnerabilities were patched in what Google classified as 'High' risk issues.
Also included in the 05 patch are fixes for three flaws in the Android Kernel, two elevation-of-privilege (CVE-2020-0255, CVE-2020-12464) and one information-leaking bug (CVE-2019-16746). MediaTek components, specifically the Multimedia Processing Driver, accounted for three elevation-of-privilege bugs (CVE-2020-0252, CVE-2020-0253, CVE-2020-0260) and two information-disclosure flaws (CVE-2020-0251, CVE-2020-0254).
Google made no mention of any of the bugs being actively targeted in the wild, which is good news.
Those running Google-branded devices should be able to get the security updates now, while everyone else will need to wait on their respective hardware vendor or carrier to get around to validating and releasing the patches. Which could be now, next week, next month, next quarter, or never, depending on your situation.
This month could be a particularly busy one, in terms of patching, as both the Black Hat and DEF CON conferences are set to kick off online this week, and both tend to bring about high-profile bug disclosures. ®
Get our [3]Tech Resources
[1] https://source.android.com/security/bulletin/2020-08-01
[2] https://www.theregister.com/2020/07/15/outlook_patch_crashes/
[3] https://whitepapers.theregister.com/
Re: I hate to say it...
I have learned this the hard way - the total TCO of an iPhone is lower even if the initial cost is higher.
If you want new shiny quick and cheap and are landfill-friendy, buy Android. Otherwise smartphones are just seeing incremental changes and reasons to upgrade are external.
For a phone to use till it breaks, it's iPhone. The 6s from 5 years ago is still being updated and plenty snappy.
My Android flagship from the same time has had no updates for three years, sluggish with the last os upgrade, and buggy with other free ROMs.
Re: I hate to say it...
I got my monthly android update from my Note 8 yesterday, that's a three year old phone on the 23rd of this month.
It's still listed under monthly support though one could imagine it moving to quarterly support after this month:
https://security.samsungmobile.com/workScope.smsb
Average lifespan of the non-removable batteries is three years so can't see them wasting much more time on it after that and four years support is an average for Samsung's higher end models, guessing you got a cheap model and got what you paid for.
Note20's announced today/tomorrow (depending on your timezone) so probably time for an upgrade myself (even though there's literally nothing the Note8 can't do and no need to upgrade, I really don't see the point in 5g right now as 4g is fast enough for a mobile device, there's always the shiny shiny impulse..).
Remember your money is important to us, but you information security is worthless.
Android the OS that keeps updating now/next week/next month/quartely/maybe if you are lucky/never again*.
*Delete as appropriate
Imagine if Windows (the last ubiquitous OS) allowed hardware suppliers to customise the OS so that patches would have to be released by them?
I know Google are redesigning the OS so it done properly rather the quick and dirty destroy MS and rule the world effort they did first time but that new OS will not be on 95% of existing hardware as non of teh manufactures will support it or distribute it. Google need to step up here and do something like offer an vanilla version that will work on older hardware, its not like there is a vast range of drivers like Windows supports natively (probably more windows printer drivers than there is Android drivers in total).
I hate to say it...
...But I won't be installing any of these updates. Why not? Because the Android phone I bought 3 years ago no longer gets updates. My next phone will either be a Jesus Phone (once I sell my liver and can afford one) or an Android LTS phone, which will be on the market shortly after I find and tame a unicorn.
For the last year my phone has had wifi and bluetooth turned off for good. I have uninstalled every app that isn't baked into the firmware or made my Google. It never leaves my house, I never open text messages or email on it, and it most likely is a security breach waiting to happen.