logo

Google splats device-hijacking exploited-in-the-wild Android kernel bug among others

ID: 0fcf041d-8383-5ec3-a57a-1e318f85fd81

STIX ID: report--0fcf041d-8383-5ec3-a57a-1e318f85fd81

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-08-06

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Google's August Android security bulletin fixes 46 issues, most notably CVE-2024-36971, a Linux-kernel networking-stack use-after-free (CVSS 7.8) that can enable remote code execution with system privileges and is reported to be under limited targeted exploitation—likely by commercial surveillance/spyware operators tracked by Google TAG. The bulletin also covers a critical Qualcomm multi-mode call processor bug (CVE-2024-23350) that can cause permanent denial-of-service and several high-severity elevation-of-privilege vulnerabilities in the Android Framework; users are urged to apply updates promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.