Earlier quoted context omitted.
Well, Google are themselves the vendor here. Also seems it's fixed and this might encourage manufacturers to push out an update.
I feel like this goes against responsible disclosure. Google should give the manufacturers a month to push updates themselves, just like Google would expect a month to fix an issue someone reported to them.
Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
11–20 of 236 posts
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#12> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?
I guess it informs us what not to do at the very least. Given the track record, I'm not very optimistic of the vendors pushing a patch very soon (if ever). This keeps us informed at least.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#13> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?
Well, one thing is it was apparently already publicly reported over 2 years ago by syzkaller: https://twitter.com/dvyukov/status/1180195777680986113
> No longer occurring on linux-next, probably fixed by the following commit:
> #syz fix: ANDROID: binder: remove waitqueue when thread exits.
https://groups.google.com/forum/#!msg/syzkaller-bugs/QyXdgUh...
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#14Earlier quoted context omitted.
Well, Google are themselves the vendor here. Also seems it's fixed and this might encourage manufacturers to push out an update.
Right, I realize they're the vendors, but isn't this just going to make even more people exploit the vulnerability before consumers get patches? Like actual hackers targeting random people in the wild, not merely law enforcement?
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#15> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?
You have to "install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content." I guess it informs us what not to do at the very least. Given the track record, I'm not very optimistic of the vendors pushing a patch very soon (if ever). This keeps us informed at least.
They can easily give that^ information without exposing details of the bug though?
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#16> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?
You have to "install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content." I guess it informs us what not to do at the very least. Given the track record, I'm not very optimistic of the vendors pushing a patch very soon (if ever). This keeps us informed at least.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#17> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?
Because the "bad guys" already know about the vulnerability, so there's no benefit from keeping it secret but a duty to the consumers to inform them as well - especially since the kernel patch already exists.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#18So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the Play store. Perhaps in other parts of the world it's more common...?
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#19> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?
I don't know the reasons behind that policy, but I'd guess with the exploit already being used, there is less incentive to keep silent about the issue. The opposite is true: putting more pressure on the vendors to provide patches, and disclosing any malicious actions that are already underway as soon as possible
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#20Earlier quoted context omitted.
I feel like this goes against responsible disclosure. Google should give the manufacturers a month to push updates themselves, just like Google would expect a month to fix an issue someone reported to them.
It's being actively exploited, which changes the calculus.