Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Why IT Leaders Should Rethink Backups in the Age of Ransomware

AI-driven synthetic data for rare haematological diseases

How 3D printing is shaping the future of nuclear energy

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Google’s March 2025 Android Security Update fixed two proactively exploited vulnerabilities
Identity

Google’s March 2025 Android Security Update fixed two proactively exploited vulnerabilities

userBy userMarch 4, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 4, 2025Ravi LakshmananVulnerability/Mobile Security

Proactively vulnerable vulnerabilities

Google released Android Security Bulletin every month in March 2025, addressing a total of 44 vulnerabilities.

Below is a list of two high failure vulnerabilities –

CVE-2024-43093 – Privilege escalation flaws in the “Android/Data”, “Android/OBB”, and “Android/Sandbox” directories, as well as framework components that can lead to unauthorized access to the respective subdirectories. CVE-2024-50302- Faulty privilege escalation in HID USB components of the Linux kernel. Through specially created HID reports, this could lead to a leak of uninitialized kernel memory by local attackers.

Note that CVE-2024-43093 was previously flagged by Google in its November 2024 security advisory and was actively exploited in the wild. It is not clear why the tech giant has come to issue a second alert.

Cybersecurity

The Hacker News reached out to Google for further comment. If you’ve heard of it, update the story.

Meanwhile, CVE-2024-50302 is one of three vulnerabilities taken to a zero-day exploit devised by Celebrity to infiltrate the android phones of Serbian youth activists in December 2024.

The exploit includes the use of CVE-2024-53104, CVE-2024-53197, and CVE-2024-50302 to increase privileges and deploy Android Spyware called Novispy.

All three vulnerabilities are in the Linux kernel and were patched late last year. CVE-2024-53104 was addressed to Google on Android last month.

In its advisory, Google acknowledged that both CVE-2024-43093 and CVE-2024-50302 are based on “limited targeted exploitation.”

The Mountain View-based company will release two security patch levels, 2025-03-01 and 2025-03-05, giving Android partners flexibility and address some of the similar vulnerabilities more quickly on all Android devices.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleBill banning trans athletes from female and female sports teams fails in the Senate
Next Article Cisco, Hitachi, Microsoft, and progress flaws are actively exploited.
user
  • Website

Related Posts

Why IT Leaders Should Rethink Backups in the Age of Ransomware

July 18, 2025

Hackers use GitHub repository to host Amadey Malware and Data Stealers and bypass filters

July 17, 2025

Hackers exploit flaws in apache http server to deploy linuxsys cryptocurrency miner

July 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Why IT Leaders Should Rethink Backups in the Age of Ransomware

AI-driven synthetic data for rare haematological diseases

How 3D printing is shaping the future of nuclear energy

Confusion sees India as a shortcut in competition with OpenAs

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

The Future of Process Automation is Here: Meet TwinH

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.