The February 2025 Android security updates patch 48 vulnerabilities, including a zero-day kernel vulnerability that has been exploited in the wild. This high-severity zero-day (tracked as CVE-2024-53104) is a privilege escalation security flaw in the Android Kernel's USB Video Class driver that allows authenticated local threat actors to elevate privileges in low-complexity attacks. The issue occurs because the driver does not accurately parse frames of the type UVC_VS_UNDEFINED within the uvc_parse_format function. As a result, the frame buffer size is miscalculated, leading to potential out-of-bounds writes that can be exploited in arbitrary code execution or denial-of-service attacks. In addition to this actively exploited zero-day bug, the February 2025 Android security updates also fix a critical security flaw in Qualcomm's WLAN component. Qualcomm describes this critical flaw (CVE-2024-45569) as a firmware memory corruption issue caused by an Improper Validation of Array Index weakness in WLAN host communication when parsing the ML IE due to invalid frame content. CVE-2024-45569 can be exploited by remote attackers to potentially execute arbitrary code or commands, read or modify memory, and trigger crashes in low-complexity attacks that don't require privileges or user interaction. Google released two sets of patches for February 2025, the 2025-02-01 and 2025-02-05 security patch levels. The latter includes all fixes from the first batch and additional patches for clo...
Google fixes Android kernel zero-day exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Feb 3, 2025
·Updated
Affected Software
5 affected components
Google Android
Google Android Kernel
Qualcomm WLAN
Google Android Kernel
Qualcomm WLAN
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Google issuing security updates to fix a zero-day vulnerability in the Android kernel that has been actively exploited in attacks.
2
What security implications are discussed in the article?
The article highlights the risks associated with a privilege escalation vulnerability that could allow attackers to gain unauthorized access to devices.
3
What is the specific identification number for the zero-day vulnerability?
The zero-day vulnerability is tracked as CVE-2024-53104.
4
Which products or software are affected by this vulnerability?
The affected products include Google Android and the Google Android Kernel, along with Qualcomm WLAN components.
5
How many vulnerabilities are addressed in the February 2025 security updates?
The February 2025 Android security updates patch a total of 48 vulnerabilities.