Get the App
SLTechnology News&Howtos  ›  IT Information  › 

Google's December update fixes a "critical" vulnerability: remote execution of arbitrary code without user interaction

Shulou Source: shulou.com Published: 2023-12-24 09:53:15 10月04日 Update

CTOnews.com December 5 news, Google recently released the December Android version update, a total of 85 vulnerabilities fixed, of which the tracking number CVE-2023-40088 vulnerability marked as "critical," affecting Android versions 11, 12, 12L, 13, 14.

CTOnews.com learned from the report that the vulnerability exists in an Android system component that can be executed remotely without user interaction and without additional permissions.

Google did not disclose details of the vulnerability for security reasons, only to suggest that attackers could exploit the vulnerability to remotely execute arbitrary code.

Google's update this month also fixes 84 security vulnerabilities, including CVE-2023-40077, CVE-2023-40076 and CVE-2023-45866, which exist in Android frameworks and system components and are "critical" level escalation vulnerabilities.

In addition, there is a "critical" vulnerability with tracking number CVE-2022-40507, which exists in Qualcomm's closed-source components.

Tags: Vulnerabilities Android keys components updates security versions systems code users security vulnerabilities situations reports attackers aspects permissions tags frameworks messages levels Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Docker Shulou Information MariaDB Redmi Xiaomi