{"id":36876,"date":"2019-10-31T22:14:26","date_gmt":"2019-10-31T19:14:26","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi\/"},"modified":"2019-10-31T22:14:26","modified_gmt":"2019-10-31T19:14:26","slug":"uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi","title":{"rendered":"Vuln\u00e9rabilit\u00e9 dans les puces Qualcomm, permettant d'attaquer un appareil Android via Wi-Fi","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dans la pile de puces sans fil Qualcomm <noindex><a rel=\"nofollow\" href=\"https:\/\/blade.tencent.com\/en\/advisories\/qualpwn\/\">ont \u00e9t\u00e9 identifi\u00e9es<\/a><\/noindex> trois vuln\u00e9rabilit\u00e9s connues sous le nom de code \u00ab QualPwn \u00bb. Le premier probl\u00e8me (CVE-2019-10539) permet d'attaquer \u00e0 distance des appareils fonctionnant sous Android via Wi-Fi. Le deuxi\u00e8me probl\u00e8me se trouve dans un firmware propri\u00e9taire avec une pile sans fil Qualcomm et permet d'acc\u00e9der au modem de bande de base (CVE-2019-10540). Le troisi\u00e8me probl\u00e8me <noindex><a rel=\"nofollow\" href=\"https:\/\/source.codeaurora.org\/quic\/la\/kernel\/msm-4.9\/commit\/?id=e0d510ff0fcb0778571579635b53ddd7e4caeb24\">est pr\u00e9sent<\/a><\/noindex> se situe dans le pilote icnss (CVE-2019-10538) et permet d'ex\u00e9cuter du code au niveau du noyau de la plateforme Android. En cas d'exploitation r\u00e9ussie de la combinaison de ces vuln\u00e9rabilit\u00e9s, un attaquant peut obtenir un contr\u00f4le \u00e0 distance sur l'appareil de l'utilisateur, sur lequel le Wi-Fi est activ\u00e9 (l'attaque n\u00e9cessite que la victime et l'attaquant soient connect\u00e9s au m\u00eame r\u00e9seau sans fil).<\/p>\n<p>La possibilit\u00e9 d'attaque a \u00e9t\u00e9 d\u00e9montr\u00e9e pour les smartphones Google Pixel2 et Pixel3. Selon les chercheurs, le probl\u00e8me concerne potentiellement plus de 835 000 appareils bas\u00e9s sur le SoC Qualcomm Snapdragon 835 et des puces plus r\u00e9centes (\u00e0 partir de Snapdragon 835, le firmware WLAN a \u00e9t\u00e9 int\u00e9gr\u00e9 au sous-syst\u00e8me du modem et ex\u00e9cut\u00e9 en tant qu'application isol\u00e9e dans l'espace utilisateur). Selon <noindex><a rel=\"nofollow\" href=\"https:\/\/www.qualcomm.com\/company\/product-security\/bulletins\">les donn\u00e9es<\/a><\/noindex> Qualcomm, le probl\u00e8me concerne plusieurs dizaines de puces diff\u00e9rentes. <\/p>\n<p>Actuellement, seules des informations g\u00e9n\u00e9rales sur les vuln\u00e9rabilit\u00e9s sont disponibles, les d\u00e9tails <noindex><a rel=\"nofollow\" href=\"https:\/\/www.blackhat.com\/us-19\/briefings\/schedule\/index.html#exploiting-qualcomm-wlan-and-modem-over-the-air-15481\">pr\u00e9vu<\/a><\/noindex> seront r\u00e9v\u00e9l\u00e9s le 8 ao\u00fbt lors de la conf\u00e9rence Black Hat. Les entreprises Qualcomm et Google ont \u00e9t\u00e9 inform\u00e9es des probl\u00e8mes en mars et ont d\u00e9j\u00e0 publi\u00e9 des correctifs (Qualcomm a inform\u00e9 des probl\u00e8mes dans <noindex><a rel=\"nofollow\" href=\"https:\/\/www.qualcomm.com\/company\/product-security\/bulletins\">le rapport de juin<\/a><\/noindex>, et Google a corrig\u00e9 les vuln\u00e9rabilit\u00e9s dans <noindex><a rel=\"nofollow\" href=\"https:\/\/source.android.com\/security\/bulletin\/2019-08-01.html\">la mise \u00e0 jour d'ao\u00fbt<\/a><\/noindex> de la plateforme Android). Tous les utilisateurs d'appareils sur des puces Qualcomm sont invit\u00e9s \u00e0 installer les mises \u00e0 jour disponibles.<\/p>\n<p>En plus des probl\u00e8mes li\u00e9s aux puces Qualcomm, la mise \u00e0 jour d'ao\u00fbt de la plateforme Android a \u00e9galement corrig\u00e9 une vuln\u00e9rabilit\u00e9 critique (CVE-2019-11516) dans la pile Bluetooth de Broadcom, permettant \u00e0 un attaquant d'ex\u00e9cuter son code dans le contexte d'un processus privil\u00e9gi\u00e9 en envoyant une requ\u00eate de transmission de donn\u00e9es sp\u00e9cialement con\u00e7ue. Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e dans les composants syst\u00e8me Android (CVE-2019-2130), permettant d'ex\u00e9cuter du code avec des privil\u00e8ges accrus lors du traitement de fichiers PAC sp\u00e9cialement con\u00e7us.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51228\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u0447\u0438\u043f\u043e\u0432 Qualcomm \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0435\u043f\u043e\u0434\u043d\u0435\u0441\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c &#171;QualPwn&#187;. \u041f\u0435\u0440\u0432\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 (CVE-2019-10539) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u0442\u044c \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android \u0447\u0435\u0440\u0435\u0437 Wi-Fi. \u0412\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u043f\u0440\u043e\u043f\u0440\u0438\u0435\u0442\u0430\u0440\u043d\u043e\u0439 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0435 \u0441 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u043c \u0441\u0442\u0435\u043a\u043e\u043c Qualcomm \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a baseband-\u043c\u043e\u0434\u0435\u043c\u0443 (CVE-2019-10540). \u0422\u0440\u0435\u0442\u044c\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 icnss (CVE-2019-10538) \u0438 \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-36876","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u0447\u0438\u043f\u043e\u0432 Qualcomm \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0435\u043f\u043e\u0434\u043d\u0435\u0441\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c &quot;QualPwn&quot;.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0447\u0438\u043f\u0430\u0445 Qualcomm, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u0442\u044c Android-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u043e \u0447\u0435\u0440\u0435\u0437 Wi-Fi | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u0447\u0438\u043f\u043e\u0432 Qualcomm \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0435\u043f\u043e\u0434\u043d\u0435\u0441\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c &quot;QualPwn&quot;.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:14:26+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:14:26+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9 dans les puces Qualcomm permettant d'attaquer un appareil Android via Wi-Fi | ProHoster","description":"Trois vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 identifi\u00e9es dans la pile de puces sans fil Qualcomm, connues sous le nom de code \"QualPwn\".","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0447\u0438\u043f\u0430\u0445 Qualcomm, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u0442\u044c Android-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u043e \u0447\u0435\u0440\u0435\u0437 Wi-Fi | ProHoster","og:description":"\u0412 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u0447\u0438\u043f\u043e\u0432 Qualcomm \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0435\u043f\u043e\u0434\u043d\u0435\u0441\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c &quot;QualPwn&quot;.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:14:26+00:00","article:modified_time":"2019-10-31T19:14:26+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36876","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 05:09:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:37:23","updated":"2026-01-22 05:09:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/36876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=36876"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/36876\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=36876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=36876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=36876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}