> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?
Because the "bad guys" already know about the vulnerability, so there's no benefit from keeping it secret but a duty to the consumers to inform them as well - especially since the kernel patch already exists.
Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
21–30 of 236 posts
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#22Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#23> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#24Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#25Earlier quoted context omitted.
It's being actively exploited, which changes the calculus.
"Actively exploited" by... law enforcement? Do all consumers really need to freak out about this the same way they would if hackers had access? Doesn't that detail change the calculus here?
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#26> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#27> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content. So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the P…
Similarly, Chrome is only mentioned because it's notable that it can be effective from inside its isolation if combined with a browser exploit. That likely applies to all browsers, but the article recommends to switch browsers.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#28Earlier quoted context omitted.
"Actively exploited" by... law enforcement? Do all consumers really need to freak out about this the same way they would if hackers had access? Doesn't that detail change the calculus here?
Not all law enforcements are working for the good of their people, probably.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#29Earlier quoted context omitted.
Because the "bad guys" already know about the vulnerability, so there's no benefit from keeping it secret but a duty to the consumers to inform them as well - especially since the kernel patch already exists.
How many consumers across the world would actually be at risk from NSO having details of the exploit vs. all the other "bad guys" though? Isn't there a significant distinction that's being brushed under the rug here?
We don't know, because we don't know who bought it and how widespread they deployed it.
Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access
#30I'm slightly confused: Do they mean any app or a compromised app?