{"id":114268,"date":"2024-03-12T12:25:57","date_gmt":"2024-03-12T10:25:57","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-android-14-ekspluatiruemaya-cherez-bluetooth-le"},"modified":"2024-03-12T12:25:57","modified_gmt":"2024-03-12T10:25:57","slug":"uyazvimost-v-android-14-ekspluatiruemaya-cherez-bluetooth-le","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-android-14-ekspluatiruemaya-cherez-bluetooth-le","title":{"rendered":"Vulnerabilidad en Android 14, explotada a trav\u00e9s de Bluetooth LE","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Los desarrolladores del proyecto GrapheneOS, que desarrolla una bifurcaci\u00f3n segura de la base de c\u00f3digo AOSP (Proyecto de C\u00f3digo Abierto de Android), han identificado una vulnerabilidad en la pila de Bluetooth de Android 14, que podr\u00eda permitir la ejecuci\u00f3n remota de c\u00f3digo. El problema se debe a un acceso a una zona de memoria ya liberada (use-after-free) en el c\u00f3digo de procesamiento de audio transmitido a trav\u00e9s de Bluetooth LE.     <\/p>\n<p>La vulnerabilidad se detect\u00f3 gracias a la integraci\u00f3n de protecci\u00f3n adicional en la llamada a hardened_malloc, que utiliza la extensi\u00f3n ARMv8.5 MTE (MemTag, Extensi\u00f3n de Etiquetado de Memoria), permitiendo vincular etiquetas a cada operaci\u00f3n de asignaci\u00f3n de memoria y organizar la verificaci\u00f3n de la validez en el uso de punteros para bloquear la explotaci\u00f3n de vulnerabilidades causadas por accesos a bloques de memoria ya liberados, desbordamientos de b\u00fafer, accesos antes de la inicializaci\u00f3n y utilizaci\u00f3n fuera del contexto actual.     <\/p>\n<p>El error se manifiesta a partir de la actualizaci\u00f3n de Android 14 QPR2 (Lanzamiento Trimestral de la Plataforma), publicada a principios de marzo. En la base de c\u00f3digo principal de Android 14, el mecanismo MTE est\u00e1 disponible como opci\u00f3n y a\u00fan no se aplica por defecto, pero en GrapheneOS ya se ha implementado para una protecci\u00f3n adicional, lo que permiti\u00f3 diagnosticar el error tras la actualizaci\u00f3n a Android 14 QPR2. El error provocaba un cierre inesperado al usar auriculares Bluetooth Samsung Galaxy Buds2 Pro con el firmware que incluye la protecci\u00f3n basada en MTE. El an\u00e1lisis del incidente mostr\u00f3 que el problema est\u00e1 relacionado con un acceso a memoria ya liberada en el controlador de Bluetooth LE, y no con un fallo debido a la integraci\u00f3n de MTE.      <\/p>\n<p>La vulnerabilidad se ha corregido en la versi\u00f3n GrapheneOS 2024030900 y afecta a las compilaciones para tel\u00e9fonos inteligentes que no incluyen la protecci\u00f3n de hardware adicional basada en la extensi\u00f3n MTE (MTE actualmente est\u00e1 habilitado solo para dispositivos Pixel 8 y Pixel 8 Pro). La vulnerabilidad se reproduce en los tel\u00e9fonos inteligentes Google Pixel 8 con una versi\u00f3n basada en Android 14 QPR2. En Android para los tel\u00e9fonos inteligentes de la serie Pixel 8, el modo MTE se puede habilitar en la configuraci\u00f3n para desarrolladores (\"Configuraci\u00f3n \/ Sistema \/ Opciones de desarrollador \/ Extensiones de etiquetado de memoria\"). Habilitar MTE resulta en un aumento del consumo de memoria de aproximadamente el 3%, pero no reduce el rendimiento.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60771\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 GrapheneOS, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u0435 \u043e\u0442\u0432\u0435\u0442\u0432\u043b\u0435\u043d\u0438\u0435 \u043e\u0442 \u043a\u043e\u0434\u043e\u0432\u043e\u0439 \u0431\u0430\u0437\u044b AOSP (Android Open Source Project), \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android 14, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0435\u043c \u043a \u0443\u0436\u0435 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0451\u043d\u043d\u043e\u0439 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043f\u0430\u043c\u044f\u0442\u0438 (use-after-free) \u0432 \u043a\u043e\u0434\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0437\u0432\u0443\u043a\u0430, \u043f\u0435\u0440\u0435\u0434\u0430\u0432\u0430\u0435\u043c\u043e\u0433\u043e \u0447\u0435\u0440\u0435\u0437 Bluetooth LE. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0431\u043b\u0430\u0433\u043e\u0434\u0430\u0440\u044f \u0438\u043d\u0442\u0435\u0433\u0440\u0430\u0446\u0438\u0438 \u0432 \u0432\u044b\u0437\u043e\u0432 hardened_malloc \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0439 \u0437\u0430\u0449\u0438\u0442\u044b, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-114268","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 GrapheneOS, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u0435 \u043e\u0442\u0432\u0435\u0442\u0432\u043b\u0435\u043d\u0438\u0435 \u043e\u0442 \u043a\u043e\u0434\u043e\u0432\u043e\u0439 \u0431\u0430\u0437\u044b AOSP (Android Open Source Project), \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android 14, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-android-14-ekspluatiruemaya-cherez-bluetooth-le\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Android 14, \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0447\u0435\u0440\u0435\u0437 Bluetooth LE | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 GrapheneOS, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u0435 \u043e\u0442\u0432\u0435\u0442\u0432\u043b\u0435\u043d\u0438\u0435 \u043e\u0442 \u043a\u043e\u0434\u043e\u0432\u043e\u0439 \u0431\u0430\u0437\u044b AOSP (Android Open Source Project), \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android 14, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-android-14-ekspluatiruemaya-cherez-bluetooth-le\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-03-12T10:25:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-03-12T10:25:57+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidad en Android 14, explotada a trav\u00e9s de Bluetooth LE | ProHoster","description":"Los desarrolladores del proyecto GrapheneOS, que desarrolla una bifurcaci\u00f3n segura de la base de c\u00f3digo AOSP (Proyecto de C\u00f3digo Abierto de Android), han identificado una vulnerabilidad en la pila de Bluetooth de Android 14, que podr\u00eda permitir.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-android-14-ekspluatiruemaya-cherez-bluetooth-le","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Android 14, \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0447\u0435\u0440\u0435\u0437 Bluetooth LE | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 GrapheneOS, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u0435 \u043e\u0442\u0432\u0435\u0442\u0432\u043b\u0435\u043d\u0438\u0435 \u043e\u0442 \u043a\u043e\u0434\u043e\u0432\u043e\u0439 \u0431\u0430\u0437\u044b AOSP (Android Open Source Project), \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android 14, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-android-14-ekspluatiruemaya-cherez-bluetooth-le","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-03-12T10:25:57+00:00","article:modified_time":"2024-03-12T10:25:57+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/114268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=114268"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/114268\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=114268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=114268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=114268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}