Live data from Hacker News

Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

thenextweb.com

11–20 of 236 posts

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#11
post #5
post #3

Earlier quoted context omitted.

Well, Google are themselves the vendor here. Also seems it's fixed and this might encourage manufacturers to push out an update.

I feel like this goes against responsible disclosure. Google should give the manufacturers a month to push updates themselves, just like Google would expect a month to fix an issue someone reported to them.

It's being actively exploited, which changes the calculus.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#12
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

You have to "install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content."

I guess it informs us what not to do at the very least. Given the track record, I'm not very optimistic of the vendors pushing a patch very soon (if ever). This keeps us informed at least.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#13
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

Well, one thing is it was apparently already publicly reported over 2 years ago by syzkaller: https://twitter.com/dvyukov/status/1180195777680986113

That was apparently fixed?

> No longer occurring on linux-next, probably fixed by the following commit:

> #syz fix: ANDROID: binder: remove waitqueue when thread exits.

https://groups.google.com/forum/#!msg/syzkaller-bugs/QyXdgUh...

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#14
post #4
post #3

Earlier quoted context omitted.

Well, Google are themselves the vendor here. Also seems it's fixed and this might encourage manufacturers to push out an update.

Right, I realize they're the vendors, but isn't this just going to make even more people exploit the vulnerability before consumers get patches? Like actual hackers targeting random people in the wild, not merely law enforcement?

It may depend who are targeted by this exploits, if the targets are politicians and people with high positions is better to make it public and have this people not use their phones.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#15
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

You have to "install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content." I guess it informs us what not to do at the very least. Given the track record, I'm not very optimistic of the vendors pushing a patch very soon (if ever). This keeps us informed at least.

> You have to "install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content."

They can easily give that^ information without exposing details of the bug though?

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#16
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

You have to "install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content." I guess it informs us what not to do at the very least. Given the track record, I'm not very optimistic of the vendors pushing a patch very soon (if ever). This keeps us informed at least.

Or the attacked surface has to be exposed to the browser sandbox, which apparently this one is, per: https://bugs.chromium.org/p/project-zero/issues/detail?id=19...

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#17
post #9
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

Because the "bad guys" already know about the vulnerability, so there's no benefit from keeping it secret but a duty to the consumers to inform them as well - especially since the kernel patch already exists.

How many consumers across the world would actually be at risk from NSO having details of the exploit vs. all the other "bad guys" though? Isn't there a significant distinction that's being brushed under the rug here?

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#18
> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content.

So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the Play store. Perhaps in other parts of the world it's more common...?

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#19
post #7
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

I don't know the reasons behind that policy, but I'd guess with the exploit already being used, there is less incentive to keep silent about the issue. The opposite is true: putting more pressure on the vendors to provide patches, and disclosing any malicious actions that are already underway as soon as possible

They could tell vendors about the issue earlier without telling the rest of the world earlier though, can't they?

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#20
post #11
post #5

Earlier quoted context omitted.

I feel like this goes against responsible disclosure. Google should give the manufacturers a month to push updates themselves, just like Google would expect a month to fix an issue someone reported to them.

It's being actively exploited, which changes the calculus.

"Actively exploited" by... law enforcement? Do all consumers really need to freak out about this the same way they would if hackers had access? Doesn't that detail change the calculus here?
Post reply on HN