ืคื’ื™ืขื•ืช ื‘ืฉื‘ื‘ื™ ืงื•ื•ืืœืงื•ื ื”ืžืืคืฉืจืช ืชืงื™ืคืช ืžื›ืฉื™ืจ ืื ื“ืจื•ืื™ื“ ื‘ืืžืฆืขื•ืช Wi-Fi

ื‘ืขืจื™ืžืช ื”ืฉื‘ื‘ื™ื ื”ืืœื—ื•ื˜ื™ืช ืฉืœ ืงื•ื•ืืœืงื•ื ืžื–ื•ื”ื” ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื”ืžื•ืฆื’ื•ืช ืชื—ืช ืฉื ื”ืงื•ื“ "QualPwn". ื”ื’ื™ืœื™ื•ืŸ ื”ืจืืฉื•ืŸ (CVE-2019-10539) ืžืืคืฉืจ ืœืชืงื•ืฃ ืžื›ืฉื™ืจื™ ืื ื“ืจื•ืื™ื“ ืžืจื—ื•ืง ื‘ืืžืฆืขื•ืช Wi-Fi. ื”ื‘ืขื™ื” ื”ืฉื ื™ื™ื” ืงื™ื™ืžืช ื‘ืงื•ืฉื—ื” ื”ืงื ื™ื™ื ื™ืช ืขื ื”ืžื—ืกื ื™ืช ื”ืืœื—ื•ื˜ื™ืช ืฉืœ Qualcomm ื•ืžืืคืฉืจืช ื’ื™ืฉื” ืœืžื•ื“ื ืคืก ื”ื‘ืกื™ืก (CVE-2019-10540). ื‘ืขื™ื” ืฉืœื™ืฉื™ืช ื”ื•ื•ื” ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ icnss (CVE-2019-10538) ื•ืžืืคืฉืจ ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืฉืœ ื”ืงื•ื“ ืฉืœื• ื‘ืจืžืช ื”ืงืจื ืœ ืฉืœ ืคืœื˜ืคื•ืจืžืช ืื ื“ืจื•ืื™ื“. ืื ืฉื™ืœื•ื‘ ืฉืœ ืคื’ื™ืขื•ื™ื•ืช ืืœื• ืžื ื•ืฆืœ ื‘ื”ืฆืœื—ื”, ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ืฉืœื™ื˜ื” ืžืจื—ื•ืง ืขืœ ืžื›ืฉื™ืจ ื”ืžืฉืชืžืฉ ื‘ื• ืคืขื™ืœื” Wi-Fi (ื”ืžืชืงืคื” ื“ื•ืจืฉืช ืฉื”ืงื•ืจื‘ืŸ ื•ื”ืชื•ืงืฃ ื™ื”ื™ื• ืžื—ื•ื‘ืจื™ื ืœืื•ืชื” ืจืฉืช ืืœื—ื•ื˜ื™ืช).

ื™ื›ื•ืœืช ื”ืชืงื™ืคื” ื”ื•ื“ื’ืžื” ืขื‘ื•ืจ ืกืžืืจื˜ืคื•ื ื™ื Google Pixel2 ื•-Pixel3. ื—ื•ืงืจื™ื ืžืขืจื™ื›ื™ื ืฉื”ื‘ืขื™ื” ืขืฉื•ื™ื” ืœื”ืฉืคื™ืข ืขืœ ื™ื•ืชืจ ืž-835 ืืœืฃ ืžื›ืฉื™ืจื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ Qualcomm Snapdragon 835 SoC ื•ืฉื‘ื‘ื™ื ื—ื“ืฉื™ื ื™ื•ืชืจ (ื”ื—ืœ ืžื”-Snapdragon 835, ืงื•ืฉื—ืช ื”-WLAN ืฉื•ืœื‘ื” ื‘ืชืช-ืžืขืจื›ืช ื”ืžื•ื“ื ื•ืจืฆื” ื›ืืคืœื™ืงืฆื™ื” ืžื‘ื•ื“ื“ืช ื‘ื—ืœืœ ื”ืžืฉืชืžืฉ). ืขืœ ื™ื“ื™ ืขืœ ืคื™ ืงื•ื•ืืœืงื•ื, ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืขืœ ื›ืžื” ืขืฉืจื•ืช ืฉื‘ื‘ื™ื ืฉื•ื ื™ื.

ื ื›ื•ืŸ ืœืขื›ืฉื™ื•, ืจืง ืžื™ื“ืข ื›ืœืœื™ ืขืœ ืคืจืฆื•ืช ื–ืžื™ืŸ, ื•ืคืจื˜ื™ื ืžืชื•ื›ื ืŸ ืฉื™ื™ื—ืฉืฃ ื‘-8 ื‘ืื•ื’ื•ืกื˜ ื‘ื›ื ืก Black Hat. ืงื•ื•ืืœืงื•ื ื•ื’ื•ื’ืœ ืงื™ื‘ืœื• ื”ื•ื“ืขื” ืขืœ ื”ื‘ืขื™ื•ืช ื‘ืžืจืฅ ื•ื›ื‘ืจ ืคืจืกืžื• ืชื™ืงื•ื ื™ื (ืงื•ื•ืืœืงื•ื ื”ื•ื“ื™ืขื” ืขืœ ื”ื‘ืขื™ื•ืช ื‘ ื“ื•"ื— ื™ื•ื ื™, ื•-Google ืชื™ืงื ื” ืคืจืฆื•ืช ื‘ ืื•ื’ื•ืกื˜ ืขื“ื›ื•ืŸ ืคืœื˜ืคื•ืจืžืช ืื ื“ืจื•ืื™ื“). ืœื›ืœ ื”ืžืฉืชืžืฉื™ื ื‘ืžื›ืฉื™ืจื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ืฉื‘ื‘ื™ ืงื•ื•ืืœืงื•ื ืžื•ืžืœืฅ ืœื”ืชืงื™ืŸ ืืช ื”ืขื“ื›ื•ื ื™ื ื”ื–ืžื™ื ื™ื.

ื‘ื ื•ืกืฃ ืœื‘ืขื™ื•ืช ื”ืงืฉื•ืจื•ืช ืœืฉื‘ื‘ื™ ืงื•ื•ืืœืงื•ื, ืขื“ื›ื•ืŸ ืื•ื’ื•ืกื˜ ืœืคืœื˜ืคื•ืจืžืช ืื ื“ืจื•ืื™ื“ ืžื‘ื˜ืœ ื’ื ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2019-11516) ื‘ืขืจื™ืžืช ื”-Bluetooth ืฉืœ Broadcom, ื”ืžืืคืฉืจืช ืœืชื•ืงืฃ ืœื‘ืฆืข ืืช ื”ืงื•ื“ ืฉืœื• ื‘ื”ืงืฉืจ ืฉืœ ืชื”ืœื™ืš ืžื™ื•ื—ืก ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉืช ื”ืขื‘ืจืช ื ืชื•ื ื™ื ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“. ืคื’ื™ืขื•ืช (CVE-2019-2130) ื ืคืชืจื” ื‘ืจื›ื™ื‘ื™ ืžืขืจื›ืช ืื ื“ืจื•ืื™ื“ ืฉืขืœื•ืœื” ืœืืคืฉืจ ื‘ื™ืฆื•ืข ืงื•ื“ ืขื ื”ืจืฉืื•ืช ื’ื‘ื•ื”ื•ืช ื‘ืขืช ืขื™ื‘ื•ื“ ืงื•ื‘ืฆื™ PAC ื‘ืขืœื™ ืžื‘ื ื” ืžื™ื•ื—ื“.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”