New Android zero-day affects millions of devices

Phone malware
(Image credit: Shutterstock)

Google's Project Zero security team has discovered a new zero-day exploit in Android which is already being used in the wild.

The vulnerability was found in the kernel of the Android operating system and can be utilized by an attacker to gain root access to a device.

However, since the “exploit requires little or no per-device customization”, this means that it may impact even more Android smartphones but those listed above have been tested and confirmed to be vulnerable to the zero-day by Google.

Android zero-day

While Google's Project Zero team first discovered the vulnerability, the company's Threat Analysis Group (TAG) confirmed that it had been used in real-world attacks. Both of these teams were also responsible for discovering a recent batch of zero-day vulnerabilities in Apple's iPhones.

Details regarding who is behind the Android zero-day are currently limited but Google's TAG believes that the Israel-based company NSO Group, that is known for selling exploits and surveillance tools, may be responsible.

However, when ZDNet reached out to the group they denied any involvement, saying:

"NSO did not sell and will never sell exploits or vulnerabilities. This exploit has nothing to do with NSO; our work is focused on the development of products designed to help licensed intelligence and law enforcement agencies save lives." 

There is a silver lining though as this new Android vulnerability is not as dangerous as past zero-days. While the vulnerability is rated as high severity by Google it still requires the installation of a malicious application in order to be exploited.

Google has notified its Android partners and a patch is now available on the Android Common Kernel, so expect affected device manufacturers to start rolling out updates soon.

Via ZDNet

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home.