• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
millions of android devices still don't have patches for mali

Millions of Android Devices Still Don’t Have Patches for Mali GPU Flaws

You are here: Home / General Cyber Security News / Millions of Android Devices Still Don’t Have Patches for Mali GPU Flaws
November 24, 2022

A established of five medium-severity security flaws in Arm’s Mali GPU driver has ongoing to keep on being unpatched on Android products for months, in spite of fixes unveiled by the chipmaker.

Google Challenge Zero, which identified and described the bugs, reported Arm addressed the shortcomings in July and August 2022.

“These fixes have not yet manufactured it downstream to impacted Android equipment (which include Pixel, Samsung, Xiaomi, Oppo, and other individuals),” Venture Zero researcher Ian Beer stated in a report. “Units with a Mali GPU are at present vulnerable.”

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The vulnerabilities, collectively tracked below the identifiers CVE-2022-33917 (CVSS score: 5.5) and CVE-2022-36449 (CVSS score: 6.5), problem a scenario of improper memory processing, therefore allowing a non-privileged person to attain access to freed memory.

The 2nd flaw, CVE-2022-36449, can be further more weaponized to generate outside of buffer bounds and disclose information of memory mappings, in accordance to an advisory issued by Arm. The checklist of afflicted motorists is down below –

CVE-2022-33917

  • Valhall GPU Kernel Driver: All versions from r29p0 – r38p0

CVE-2022-36449

  • Midgard GPU Kernel Driver: All versions from r4p0 – r32p0
  • Bifrost GPU Kernel Driver: All variations from r0p0 – r38p0, and r39p0
  • Valhall GPU Kernel Driver: All variations from r19p0 – r38p0, and r39p0

The results at the time yet again emphasize how patch gaps can render millions of devices susceptible at after and put them at risk of heightened exploitation by danger actors.

“Just as users are advised to patch as promptly as they can as soon as a release containing security updates is accessible, so the same applies to vendors and firms,” Beer said.

“Firms will need to stay vigilant, adhere to upstream resources intently, and do their greatest to provide total patches to buyers as before long as feasible.”

Observed this write-up intriguing? Comply with THN on Fb, Twitter  and LinkedIn to read through more distinctive written content we article.


Some pieces of this report are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Cyber Essentials Scheme Set for April 2023 Update
Next Post: Pro-Russia Killnet hackers claim DDoS attack on EU Parliament website pro russia killnet hackers claim ddos attack on eu parliament website»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.