Vulnerability in Android 14, exploited through Bluetooth LE

The developers of the GrapheneOS project, which is developing a secure branch of the AOSP (Android Open Source Project) codebase, have discovered a vulnerability in the Bluetooth stack of Android 14 that could potentially lead to remote code execution. The issue is caused by accessing a previously freed memory area (use-after-free) in the audio processing code for Bluetooth LE.

The vulnerability was identified through the integration of additional protection in the hardened_malloc call, utilizing the ARMv8.5 MTE (MemTag, Memory Tagging Extension), which allows tags to be bound to each memory allocation operation and organizes a pointer usage correctness check to block the exploitation of vulnerabilities caused by accessing freed memory blocks, buffer overflows, pre-initialization accesses, and out-of-context usage.

The error first appeared with the Android 14 QPR2 (Quarterly Platform Release) update, released in early March. In the main Android 14 codebase, the MTE mechanism is available as an option and is currently not used by default, but in GrapheneOS it has already been implemented for additional protection, allowing the diagnosis of the error after updating to Android 14 QPR2. The error caused crashes when using Samsung Galaxy Buds2 Pro Bluetooth headphones with firmware that includes MTE-based protection. An analysis of the incident revealed that the issue was related to accessing freed memory in the Bluetooth LE handler, rather than a failure due to the integration of MTE.

The vulnerability has been fixed in GrapheneOS release 2024030900 and affects builds for smartphones that do not have additional hardware protection based on the MTE extension enabled (MTE is currently enabled only for Pixel 8 and Pixel 8 Pro devices). The vulnerability can be reproduced on Google Pixel 8 smartphones with firmware based on Android 14 QPR2. In Android for Pixel 8 smartphones, the MTE mode can be enabled in the developer options ('Settings / System / Developer options / Memory Tagging Extensions'). Enabling MTE increases memory consumption by about 3%, but does not decrease performance.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster