Zimperium Applauds Google’s Rapid Response to Unpatched Kernel Exploit
ID: cf5330fb-af16-5bf6-898a-bf625dbb3b83
STIX ID: report--cf5330fb-af16-5bf6-898a-bf625dbb3b83
Feed Name: Zimperium Blog
Threat Score
Zimperium discovered and reported an in-the-wild local kernel privilege escalation (CVE-2015-1805) used by the KingRoot rooting app to gain persistent root on Android devices with kernel versions 3.4, 3.10 and 3.14 (including Nexus 5/6). Google issued an emergency AOSP patch on March 18, 2016; the advisory includes mitigations such as Verify Apps blocking and recommends restricting installs from unknown sources and applying vendor updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
