A vulnerability in Android allows remote code execution when Bluetooth is enabled.

In February the official blog says nothing about release dates, but the creators shared gameplay fragments from a new demo intended for internal testing. the Android platform has addressed a critical vulnerability (CVE-2020-0022) issue in the Bluetooth stack, allowing for remote code execution through sending a specially crafted Bluetooth packet. The problem can be exploited unnoticed by an attacker within Bluetooth range. There's a possibility of using this vulnerability to create worms that infect adjacent devices.

To carry out the attack, the attacker only needs to know the victim device's MAC address (no prior pairing is required, but Bluetooth must be enabled on the device). On some devices, the Bluetooth MAC address can be calculated from the Wi-Fi MAC address. If successfully exploited, the attacker can execute their code with the permissions of the background process managing Bluetooth in Android.
This issue is specific to the Bluetooth stack used in Android Fluoride (based on the BlueDroid project code from Broadcom) and does not occur in the BlueZ stack used in Linux.

Researchers who identified the problem have been able to prepare a working exploit prototype, but details of the exploitation will be disclosed later, after the fix has been rolled out to the majority of users. It is only known that the vulnerability exists in the packet reassembly code and is caused by incorrect calculation of L2CAP (Logical Link Control and Adaptation Protocol) packet sizes when the data sent by the sender exceeds the expected size.

In Android 8 and 9, the issue can lead to code execution, but in Android 10 it is limited to crashing the Bluetooth background process. Older versions of Android are potentially affected by the issue, but the possibility of exploiting the vulnerability has not been tested. Users are advised to install the firmware update as soon as possible, and if that is not possible, to disable Bluetooth by default, prevent device discovery, and activate Bluetooth in public places only when absolutely necessary (including switching from wireless to wired headphones).

In addition to the noted issue in February the security patch set for Android fixes 26 vulnerabilities, with another vulnerability (CVE-2020-0023) rated as critical. The second vulnerability also affects The Bluetooth stack is associated with incorrect handling of the BLUETOOTH_PRIVILEGED privilege in setPhonebookAccessPermission. Regarding vulnerabilities labeled as critical, 7 issues have been fixed in frameworks and applications, 4 in system components, 2 in the kernel, and 10 in open and proprietary components for Qualcomm chips.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster