Google has released its February Android security updates, including a fix for a high-severity kernel-level vulnerability, which is suspected to be in use by targeted exploits. The flaw, CVE-2024-53104, is an intriguing Linux kernel flaw in its USB video-class driver code. There's not a lot of detail about the bug, other than the fix is to skip the parsing of undefined video frames that would otherwise cause the kernel to write to memory it's not supposed to, which could be used to crash or fully hijack a device. What's interesting is that this driver code is supposed to mainly handle USB cameras and similar video sources. Thus, exploitation potentially involves connecting some malicious hardware that feeds bad data into the system. Google indicated the flaw can be used to achieve "physical escalation of privilege with no additional execution privileges needed," which to us sounds like someone being able to plug a malicious gadget – perhaps something law enforcement might use – into a vulnerable Android device and taking it over. Very curious. CVE-2024-53104 may be under limited, targeted exploitation "There are indications that CVE-2024-53104 may be under limited, targeted exploitation," Google said in its advisory. We note that a patch to address the hole in the open source kernel was accepted at the end of last year. Of the 46 patches pushed out by Google this month, only one is rated as "critical" by the ad slinger: CVE-2024-45569, with a CVSS rating of 9.8 out of 10. The...
Google warns Android users of a kernel flaw under attack
The Register
·Iain Thomson
·Published Feb 4, 2025
·Updated
Affected Software
13 affected components
Google Android
Linux Kernel
Qualcomm wireless LAN stack
Qualcomm camera drivers
Imagination Technologies PowerVR-GPU
Netgear Nighthawk XR1000
Netgear Nighthawk XR1000v2
Netgear Nighthawk XR500
Netgear Wi-Fi 6 WAX206
Netgear Wi-Fi 6 WAX214v2
Netgear Wi-Fi 6 WAX220
Google Android
Linux Kernel
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a high-severity kernel vulnerability in Android that Google addressed with its February security updates.
2
What security implications are discussed?
The article highlights that the vulnerability, CVE-2024-53104, is actively being exploited in targeted attacks.
3
What products or software are affected?
Affected products include Google Android, various Netgear routers like the Nighthawk XR1000 and Wi-Fi 6 models, and components related to the Linux kernel.
4
How can users protect themselves from this vulnerability?
Users are advised to update their Android devices and affected Netgear products as soon as possible to mitigate the risk.
5
Who is the vendor of the kernel flaw?
The flaw is associated with the Linux kernel, but it primarily impacts Android devices developed by Google.