I-Google izodalula ulwazi olumayelana nokuba sengozini kumadivayisi e-Android enkampani yangaphandle

Google kwethulwe isinyathelo I-Android Partner Vulnerability, ehlela ukudalula idatha emayelana nokuba sengozini kumadivayisi e-Android avela kubakhiqizi abahlukahlukene be-OEM. Isinyathelo sizoyenza icace kakhudlwana kubasebenzisi mayelana nokuba sengozini okuqondene ne-firmware enezinguquko ezivela kubakhiqizi bezinkampani zangaphandle.

Kuze kube manje, imibiko esemthethweni yokuba sengozini (Amabhulethini Okuvikela e-Android) ibonise kuphela izinkinga kukhodi eyinhloko enikezwa endaweni yesikhombi se-AOSP, kodwa ayizange icabangele izinkinga eziqondene nokulungiswa kwama-OEM. Kakade kwembulwa Izinkinga zithinta abakhiqizi abafana ne-ZTE, Meizu, Vivo, OPPO, Digitime, Transsion kanye neHuawei.

Phakathi kwezinkinga ezikhonjiwe:

  • Kumadivayisi e-Digitime, esikhundleni sokuhlola izimvume ezengeziwe zokufinyelela i-API yesevisi yokufaka isibuyekezo se-OTA yasetshenziswa iphasiwedi enekhodi eqinile evumela umhlaseli ukuthi afake amaphakheji e-APK buthule futhi aguqule izimvume zohlelo lokusebenza.
  • Kwesinye isiphequluli esidumile kwamanye ama-OEM Phoenix umphathi wephasiwedi kwasetshenziswa ngendlela yekhodi ye-JavaScript esebenza kumongo wekhasi ngalinye. Isayithi elilawulwa umhlaseli lingathola ukufinyelela okugcwele kusitoreji sephasiwedi yomsebenzisi, esibethelwe kusetshenziswa i-algorithm ye-DES engathembekile kanye nokhiye onekhodi eqinile.
  • Uhlelo lwe-UI yesistimu kumadivayisi we-Meizu kulayishiwe ikhodi eyengeziwe evela kunethiwekhi ngaphandle kokubethela nokuqinisekisa uxhumano. Ngokugada ithrafikhi ye-HTTP yesisulu, umhlaseli angasebenzisa ikhodi yakhe kumongo wohlelo lokusebenza.
  • Amadivayisi e-Vivo abenawo kwenziwe kabusha Indlela ye-checkUidPermission yekilasi le-PackageManagerService ukuze inikeze izimvume ezengeziwe kwezinye izinhlelo zokusebenza, ngisho noma lezi zimvume zingacacisiwe kufayela le-manifest. Enguqulweni eyodwa, indlela inikeze noma yiziphi izimvume ezinhlelweni zokusebenza ngesihlonzi esithi com.google.uid.shared. Kwenye inguqulo, amagama ephakheji aye ahlolwa ngokumelene nohlu ukuze kunikezwe izimvume.

Source: opennet.ru

Engeza amazwana