May Android security updates patch 4 zero-days exploited in the wild
According to info provided by Google's Project Zero team, four Android security vulnerabilities were exploited in the wild before being patched earlier this month.
Attacks attempting to exploit these flaws were targeted and impacted a limited number of users based on information shared after this month's Android security updates were published.
"There are indications that CVE-2021-1905, CVE-2021-1906, CVE-2021-28663 and CVE-2021-28664 may be under limited, targeted exploitation," a recently updated version of the May 2021 Android Security Bulletin reveals. The four Android vulnerabilities impact Qualcomm GPU and Arm Mali GPU Driver components.
This month's Android security updates also include patches for critical vulnerabilities (CVE-2021-0473, CVE-2021-0474, CVE-2021-0475) in the System component that could be exploited by remote attackers using specially crafted files to execute arbitrary malicious code within the context of a privileged process.
Source: bleepingcomputer.com
20 May 2021