Rewterz
Rewterz Threat Alert – Remcos RAT – Active IOCs
March 12, 2024
Rewterz
Rewterz Threat Advisory – Multiple Google Android Vulnerabilities
March 13, 2024

Rewterz Threat Advisory – Multiple Google Android Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-27206 CVSS:7.5

Google Android could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information.

CVE-2024-27224 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in strncpy of strncpy.c. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27222 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by the Intent Redirect GRANT_URI_PERMISSIONS Attack in onSkipButtonClick of FaceEnrollFoldPage.java. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27212 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in init_data. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27219 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in tmu_set_pi of tmu.c. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27221 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in update_policy_data. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27220 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds memory access in lpm_req_handler. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27211 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in AtiHandleAPOMsgType of ati_Main.c. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27213 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an use-after-free in BroadcastSystemMessage of servicemgr.cpp. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27210 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in policy_check of fvp.c. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27229 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in policy_check of fvp.c. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27228 CVSS:8.4

Google Android could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2024-27226 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in tmu_config_gov_params. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27236 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by a type confusion in aoc_unlocked_ioctl of aoc.c. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

CVE-2024-27233 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by uninitialized data in ppcfw_init_secpolicy of ppcfw.c. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

Impact

  • Information Disclosure
  • Privilege Escalation

Indicators Of Compromise

CVE

  • CVE-2024-27206
  • CVE-2024-27224
  • CVE-2024-27222
  • CVE-2024-27212
  • CVE-2024-27219
  • CVE-2024-27221
  • CVE-2024-27220
  • CVE-2024-27211
  • CVE-2024-27213
  • CVE-2024-27210
  • CVE-2024-27229
  • CVE-2024-27228
  • CVE-2024-27226
  • CVE-2024-27236
  • CVE-2024-27233

Affected Vendors

Google

Affected Products

  • Google Android

Remediation

Upgrade to the latest version of Android available from the Google Website.

Google Website