ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ Samsung Exynos ื•ื•ื™ื™ืจืœื™ืก ืžืึทื“ื–ืฉื•ืœื– ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ื“ื•ืจืš ื“ื™ ืื™ื ื˜ืขืจื ืขื˜

ืจืขืกืขืึทืจื˜ืฉืขืจืก ืคื•ืŸ ื“ื™ Google Project Zero ืžืึทื ืฉืึทืคึฟื˜ ื’ืขืžืืœื“ืŸ ื“ื™ ืœืขื’ื™ื˜ื™ืžืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹18 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ Samsung Exynos 5G/LTE/GSM ืžืึธื“ืขืžืก. ื“ื™ ืคื™ืจ ืžืขืจืกื˜ ื’ืขืคืขืจืœืขืš ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2023-24033) ืœืึธื–ืŸ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืื•ื™ืฃ ื“ื™ ื‘ืึทืกืขื‘ืึทื ื“ ืฉืคึผืึธืŸ ืžื“ืจื’ื” ื“ื•ืจืš ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทืŸ ืคื•ืŸ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืื™ื ื˜ืขืจื ืขื˜ ื ืขื˜ื•ื•ืึธืจืงืก. ืœื•ื™ื˜ ืคืืจืฉื˜ื™ื™ืขืจืก ืคื•ืŸ ื’ื•ื’ืœ ืคึผืจืึธื™ืขืงื˜ ื ื•ืœ, ื ืึธืš ืงืึทื ื“ืึทืงื˜ื™ื ื’ ืึท ื‘ื™ืกืœ ื ืึธืš ืคืึธืจืฉื•ื ื’, ื‘ืึธืงืข ืึทื˜ืึทืงืขืจื– ืงืขื ืขืŸ ื’ืขืฉื•ื•ื™ื ื“ ืฆื•ื’ืจื™ื™ื˜ืŸ ืึท ืืจื‘ืขื˜ืŸ ื’ื•ื•ื•ืจืข ื•ื•ืึธืก ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ืจื™ืžืึธื•ื˜ืœื™ ื‘ืึทืงื•ืžืขืŸ ืงืึธื ื˜ืจืึธืœ ืื•ื™ืฃ ื“ื™ ื•ื•ื™ื™ืจืœื™ืก ืžืึธื“ื•ืœืข ืžื“ืจื’ื”, ื ืึธืจ ื•ื•ื™ืกืŸ ื“ื™ ื˜ืขืœืขืคืึธืŸ ื ื•ืžืขืจ ืคื•ืŸ ื“ื™ ืงืึธืจื‘ืŸ. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืึทื ื ืึธื•ื˜ื™ืกื˜ ื“ื•ืจืš ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ื“ืึทืจืคืŸ ืื™ื ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืงื™ื™ืŸ ืึทืงืฉืึทื ื–.

ื“ื™ ืจื•ืขืŸ 14 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื”ืึธื‘ืŸ ืึท ื ื™ื“ืขืจื™ืงืขืจ ืฉื˜ืจืขื ื’ืงื™ื™ึทื˜ ืžื“ืจื’ื”, ื–ื™ื ื˜ ื“ื™ ื‘ืึทืคืึทืœืŸ ืจื™ืงื•ื•ื™ื™ืขืจื– ืึทืงืกืขืก ืฆื• ื“ื™ ืจื™ืจืขื•ื•ื“ื™ืง ื ืขืฅ ืึธืคึผืขืจืึทื˜ืึธืจ ืก ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ ืึธื“ืขืจ ื”ื™ื’ืข ืึทืงืกืขืก ืฆื• ื“ื™ ื‘ืึทื ื™ืฆืขืจ 'ืก ืžื™ื˜ืœ. ืžื™ื˜ ื“ื™ ื•ื™ืกื ืขื ืคื•ืŸ CVE-2023-24033, ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ืคึผืึทื˜ืฉื˜ ืื™ืŸ ืึท ืžืึทืจืฅ ืคื™ืจืžื•ื•ืึทืจืข ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืคึฟืึทืจ Google ืคึผื™ืงืกืขืœ ื“ืขื•ื•ื™ืกืขืก, ื“ื™ ื™ืฉื•ื– ื‘ืœื™ื™ื‘ืŸ ืึทื ืคึผืึทื˜ืฉื˜. ืึทืœืข ื•ื•ืึธืก ืื™ื– ื‘ืึทื•ื•ื•ืกื˜ ื•ื•ืขื’ืŸ ื“ื™ CVE-2023-24033 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืึทื– ืขืก ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ืคืึทืœืฉ ื˜ืฉืขืง ืคื•ืŸ ื“ื™ ืคึฟืึธืจืžืึทื˜ ืคื•ืŸ ื“ื™ "ืึทืงืกืขืคึผื˜ื™ื ื’ ื˜ื™ืคึผ" ืึทื˜ืจื™ื‘ื™ื•ื˜ ื˜ืจืึทื ืกืžื™ื˜ื˜ืขื“ ืื™ืŸ SDP (ืกืขืกื™ืข ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’ ืคึผืจืึธื˜ืึธืงืึธืœ) ืึทืจื˜ื™ืงืœืขืŸ.

ื‘ื™ื– ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ื“ื•ืจืš ืžืึทื ื™ืึทืคืึทืงื˜ืฉืขืจืขืจื–, ื™ื•ื–ืขืจื– ื–ืขื ืขืŸ ืึทื“ื•ื•ื™ื™ื–ื“ ืฆื• ื“ื™ืกื™ื™ื‘ืึทืœ VoLTE (Voice-over-LTE) ืฉื˜ื™ืฆืŸ ืื•ืŸ ื“ื™ Wi-Fi ืคืึทืš ืคื•ื ืงืฆื™ืข ืื™ืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื™ืŸ ื“ืขื•ื•ื™ืกืขืก ื™ืงื•ื•ื™ืคึผื˜ ืžื™ื˜ ืขืงืกื™ื ืึธืก ื˜ืฉื™ืคึผืก, ืœืžืฉืœ, ืื™ืŸ ืกืึทืžืกื•ื ื’ ืกืžืึทืจื˜ืคืึธื ืขืก (S22, M33, M13, M12, A71, A53, A33, A21, A13, A12 ืื•ืŸ A04), Vivo (S16, S15, S6, X70, X60 ืื•ืŸ X30), Google Pixel (6 ืื•ืŸ 7), ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื•ื•ืขืจืึทื‘ืึทืœ ื“ืขื•ื•ื™ืกืขืก ืžื™ื˜ ื“ื™ Exynos W920 ื˜ืฉื™ืคึผืกืขื˜ ืื•ืŸ ืึธื˜ืึทืžืึธื•ื˜ื™ื•ื• ืกื™ืกื˜ืขืžืขืŸ ืžื™ื˜ ื“ื™ Exynos Auto T5123 ืฉืคึผืึธืŸ.

ืจืขื›ื˜ ืฆื• ื“ืขืจ ื’ืขืคืึทืจ ืคื•ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื•ืŸ ื“ื™ ืคืึทืงื˜ ืคื•ืŸ ื“ื™ ื’ื™ืš ื™ืžืขืจื“ื–ืฉืึทื ืก ืคื•ืŸ ืึท ื’ื•ื•ื•ืจืข, Google ื‘ืึทืฉืœืึธืกืŸ ืฆื• ืžืึทื›ืŸ ืึท ื•ื™ืกื ืขื ืฆื• ื“ื™ ื”ืขืจืฉืŸ ืคึฟืึทืจ ื“ื™ 4 ืžืขืจืกื˜ ื’ืขืคืขืจืœืขืš ืคึผืจืึธื‘ืœืขืžืก ืื•ืŸ ืคืึทืจื”ืึทืœื˜ืŸ ื“ื™ ืึทื ื˜ืคึผืœืขืงื•ื ื’ ืคื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ ื“ื™ ืคืจืื‘ืœืขืžืขืŸ. ืคึฟืึทืจ ืื ื“ืขืจืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ื“ืขื˜ืึทื™ืœืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื™ืกืงืœืึธื•ื–ื“ 90 ื˜ืขื’ ื ืึธืš ืคืึทืจืงื•ื™ืคืขืจ ืึธื ื–ืึธื’ (ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– CVE-2023-26072, CVE-2023-26073, CVE-2023-26074, CVE-2023-26075 ืื•ืŸ CVE-2023-26076 ืื™ื– ืฉื•ื™ืŸ ื‘ื ื™ืžืฆื ืื™ืŸ 9 ื–ืฉื•ืง ื˜ืจืึทืงื™ื ื’ ืกื™ืกื˜ืขื, ืื•ืŸ ืคึฟืึทืจ ื“ื™ ืจื•ืขืŸ 90 ื™ืฉื•ื– ื“ื™ 2023-ื˜ืึธื’ ื•ื•ืืจื˜ืŸ ืฆื™ื™ึทื˜ ืื™ื– ื ื™ืฉื˜ ื ืึธืš ืื•ื™ืกื’ืขื’ืื ื’ืขืŸ). ื“ื™ ืจืขืคึผืึธืจื˜ืขื“ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– CVE-2607-XNUMX * ื–ืขื ืขืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ื•ื•ืขืŸ ื“ื™ืงืึธื•ื“ื™ื ื’ ื–ื™ื›ืขืจ ืึธืคึผืฆื™ืขืก ืื•ืŸ ืจืฉื™ืžื•ืช ืื™ืŸ ื“ื™ NrmmMsgCodec ืื•ืŸ NrSmPcoCodec ืงืึธื“ืขืงืก.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’