"Android’s January 2024 Security Update Patches 58 Vulnerabilities"

Google recently released patches for 58 vulnerabilities in the Android platform and fixes for three security bugs in Pixel devices.  The first part of Android’s January 2024 update, which arrives on devices as the 2024-01-01 security patch level, addresses ten security holes in the Framework and System components, all rated high severity.  Google noted that the most severe of these issues is a security vulnerability in the Framework component that could lead to local escalation of privilege with no additional execution privileges needed.  Google says the security update resolves five flaws in the Framework component, including four elevation of privilege and one information disclosure bug.  Five other issues were addressed in the System component, including one elevation of privilege and four information disclosure defects.  The second part of the update, the 2024-01-05 security patch level, includes patches for 48 vulnerabilities in Arm, Imagination Technologies, MediaTek, Unisoc, and Qualcomm components.  Google noted that while most of the resolved bugs have a severity rating of high, three issues in Qualcomm components are rated critical.  Google makes no mention of any of these vulnerabilities being exploited in attacks.  However, users are advised to update their devices as soon as possible.

 

SecurityWeek reports: "Android’s January 2024 Security Update Patches 58 Vulnerabilities"

Submitted by Adam Ekwall on