Live data from Hacker News

Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

thenextweb.com

1–10 of 236 posts

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#2
> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android.

> Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android.

Why is this a good idea?

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#3
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

Well, Google are themselves the vendor here. Also seems it's fixed and this might encourage manufacturers to push out an update.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#4
post #3
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

Well, Google are themselves the vendor here. Also seems it's fixed and this might encourage manufacturers to push out an update.

Right, I realize they're the vendors, but isn't this just going to make even more people exploit the vulnerability before consumers get patches? Like actual hackers targeting random people in the wild, not merely law enforcement?

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#5
post #3
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

Well, Google are themselves the vendor here. Also seems it's fixed and this might encourage manufacturers to push out an update.

I feel like this goes against responsible disclosure. Google should give the manufacturers a month to push updates themselves, just like Google would expect a month to fix an issue someone reported to them.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#6
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

Well, one thing is it was apparently already publicly reported over 2 years ago by syzkaller:

https://twitter.com/dvyukov/status/1180195777680986113

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#7
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

I don't know the reasons behind that policy, but I'd guess with the exploit already being used, there is less incentive to keep silent about the issue. The opposite is true: putting more pressure on the vendors to provide patches, and disclosing any malicious actions that are already underway as soon as possible

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#8
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

The general reasoning is that since it's already being exploited, there's more value in warning people so they can decide to not use said affected devices, rather than being in the dark.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#9
post #2

> The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android. > Due to evidence of in the wild exploit, we are now de-restricting this bug 7 days after reporting to Android. Why is this a good idea?

Because the "bad guys" already know about the vulnerability, so there's no benefit from keeping it secret but a duty to the consumers to inform them as well - especially since the kernel patch already exists.

Re: Google, Xiaomi, and Huawei affected by zero-day flaw that unlocks root access

#10
People, many on this very site, often erroneously claim that P0 does not disclose vulnerabilities in Google's own products. Or they claim that Google gets favorable treatment, like the disclosure only of less severe bugs, or longer disclosure deadlines. Here is a countervailing datapoint.
Post reply on HN