• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
google using clang sanitizers to protect android against cellular baseband

Google Using Clang Sanitizers to Protect Android Against Cellular Baseband Vulnerabilities

You are here: Home / General Cyber Security News / Google Using Clang Sanitizers to Protect Android Against Cellular Baseband Vulnerabilities
December 13, 2023

Google is highlighting the job performed by Clang sanitizers in hardening the security of the mobile baseband in the Android functioning process and preventing specific forms of vulnerabilities.

This includes Integer Overflow Sanitizer (IntSan) and BoundsSanitizer (BoundSan), both of those of which are section of UndefinedBehaviorSanitizer (UBSan), a device created to catch various forms of undefined habits during program execution.

“They are architecture agnostic, ideal for bare-steel deployment, and really should be enabled in present C/C++ code bases to mitigate mysterious vulnerabilities,” Ivan Lozano and Roger Piqueras Jover explained in a Tuesday article.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Upcoming WEBINAR Defeat AI-Powered Threats with Zero Believe in – Webinar for Security Professionals

Standard security measures will not lower it in today’s globe. It is time for Zero Have confidence in Security. Protected your info like in no way ahead of.

Join Now

The advancement will come months following the tech giant said it really is working with ecosystem associates to improve the security of firmware that interacts with Android, thereby generating it challenging for danger actors to attain distant code execution within just the Wi-Fi SoC or the cellular baseband.

IntSan and BoundSan are two of the compiler-centered sanitizers that Google has enabled as an exploit mitigation measure to detect arithmetic overflows and execute bounds checks about array accesses, respectively.

Google acknowledged that when equally BoundSan and IntSan incur a sizeable effectiveness overhead, it has enabled it in security-critical attack surfaces forward of a complete-fledged rollout over the total codebase. This covers –

  • Capabilities parsing messages delivered around the air in 2G, 3G, 4G, and 5G
  • Libraries encoding/decoding advanced formats (e.g., ASN.1, XML, DNS, and so on.)
  • IMS, TCP, and IP stacks, and
  • Messaging features (SMS, MMS)

“In the particular situation of 2G, the greatest system is to disable the stack entirely by supporting Android’s ‘2G toggle,'” the scientists mentioned. “Having said that, 2G is however a essential cellular accessibility technology in sure components of the earth and some users could need to have this legacy protocol enabled.”

Cybersecurity

It is really worth noting that the “tangible” added benefits arising out of deploying sanitizers notwithstanding, they do not handle other courses of vulnerabilities, such as individuals similar to memory safety, necessitating a changeover of the codebase to a memory-protected language like Rust.

In early Oct 2023, Google announced that it experienced rewritten the Android Virtualization Framework’s (AVF) shielded VM (pVM) firmware in Rust to present a memory-harmless basis for the pVM root of believe in.

“As the substantial-amount operating program turns into a extra challenging focus on for attackers to productively exploit, we anticipate that lessen level parts these as the baseband will appeal to extra focus,” the researchers concluded.

“By applying contemporary toolchains and deploying exploit mitigation technologies, the bar for attacking the baseband can be elevated as nicely.”

Identified this report attention-grabbing? Follow us on Twitter  and LinkedIn to read much more distinctive content material we put up.


Some sections of this article are sourced from:
thehackernews.com

Previous Post: «how to analyze malware's network traffic in a sandbox How to Analyze Malware’s Network Traffic in A Sandbox
Next Post: BazaCall Phishing Scammers Now Leveraging Google Forms for Deception bazacall phishing scammers now leveraging google forms for deception»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.