{"id":243869,"date":"2021-05-06T21:17:43","date_gmt":"2021-05-06T18:17:43","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/qualcomm-is-patching-a-critical-bug-on-android-review-geek\/"},"modified":"2021-05-06T21:17:43","modified_gmt":"2021-05-06T18:17:43","slug":"qualcomm-is-patching-a-critical-bug-on-android-review-geek","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/qualcomm-is-patching-a-critical-bug-on-android-review-geek\/","title":{"rendered":"#Qualcomm is Patching a Critical Bug on Android \u2013 Review Geek"},"content":{"rendered":"<p><strong>&#8220;#Qualcomm is Patching a Critical Bug on Android \u2013 Review Geek&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 1920px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage wp-image-81544 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/05\/f9c530cb.png?width=1200\" alt=\"Qualcomm logo on a smartphone in front of a laptop\" width=\"1920\" height=\"1080\" data-crediturl=\"https:\/\/www.shutterstock.com\/image-photo\/april-25-2019-brazil-qualcomm-logo-1380826139\" data-credittext=\"rafapress\/Shutterstock.com\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.shutterstock.com\/image-photo\/april-25-2019-brazil-qualcomm-logo-1380826139\">rafapress\/Shutterstock.com<\/a><\/span><\/figcaption><\/figure>\n<p><span>Recently, a critical chip flaw was discovered in Qualcomm\u2019s Mobile Station Modem (MSM), a system of chips that run on nearly one third of the world\u2019s smartphones, mostly higher-end devices. Now, a fix for the vulnerability is headed to Android devices.<\/span><\/p>\n<p><span>The bug was discovered by researchers at <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/research.checkpoint.com\/\"><span>Check Point Research<\/span><\/a><span>. The MSM helps run things like SMS, voice, and high-definition recording and is primarily found on higher-end devices from LG, Samsung, Xiaomi, Google, and OnePlus. Phone manufacturers can add on to the functionality of these chips to handle tasks like SIM unlock requests.<\/span><\/p>\n<p><span>The root of the problem is that the buffer overflow can be exploited by malicious <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a> installations which can then plant malicious and nearly undetectable code into the device\u2019s MSM that can potentially affect some of the device\u2019s most vital functions.<\/span><\/p>\n<p><span>\u201cThis means an attacker could have used this vulnerability to inject malicious code into the modem from Android, giving them access to the device user\u2019s call history and SMS, as well as the ability to listen to the device user\u2019s conversations,\u201d stated the researchers. \u201cA hacker can also exploit the vulnerability to unlock the device\u2019s SIM, thereby overcoming the limitations imposed by service providers on it.\u201d<\/span><\/p>\n<figure style=\"width: 1600px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-81545 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/05\/2d4812cb.png\" alt=\"Developer programmer typing code for a website in an office\" width=\"1600\" height=\"900\" data-crediturl=\"https:\/\/www.shutterstock.com\/image-photo\/developing-programmer-development-website-design-coding-1331627603\" data-credittext=\"Joyseulay\/Shutterstock.com\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.shutterstock.com\/image-photo\/developing-programmer-development-website-design-coding-1331627603\">Joyseulay\/Shutterstock.com<\/a><\/span><\/figcaption><\/figure>\n<p><span>A spokesperson from Check Point Research, Ekram Ahmed, told <\/span><i><span>Ars Technica<\/span><\/i><span> that Qualcomm has released a patch and disclosed the bug to all affected customers. \u201cFrom our experience, the implementation of these fixes takes time, so some of the phones may still be prone to the threat. Accordingly, we decided not to share all the technical details, as it would give hackers a roadmap on how to orchestra an exploitation.\u201d<\/span><\/p>\n<p><span>Likewise, Qualcomm released a statement saying \u201cProviding technologies that support robust security and privacy is a priority for Qualcomm. We commend the security researchers from Check Point for using industry-standard coordinated disclosure practices. Qualcomm Technologies has already made fixes available to OEMs in December 2020, and we encourage end users to update their devices as patches become available.\u201d\u00a0<\/span><\/p>\n<p><span>The chip flaw, tracked as CVE-2020-11292 was discovered using a process called fuzzing. The process exposes the chip system to unusual inputs which then help detect bugs in the firmware. While the implications of the vulnerability are frightening, they\u2019ve also given security researchers more information and will make future security measures and detection easier.<\/span><\/p>\n<p><small><span>via <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/gadgets\/2021\/05\/fix-for-critical-qualcomm-chip-flaw-is-making-its-way-to-android-devices\/\"><span>Ars Technica<\/span><\/a><\/small>\n<\/div>\n<p><script>\nsetTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s)}(window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n  fbq('init', '1137093656460433');\n  fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.reviewgeek.com\/81540\/qualcomm-is-patching-a-critical-bug-on-android\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Qualcomm is Patching a Critical Bug on Android \u2013 Review Geek&#8221; rafapress\/Shutterstock.com Recently, a critical chip flaw was discovered in Qualcomm\u2019s Mobile Station Modem (MSM), a system of chips that run on nearly one third of the world\u2019s smartphones, mostly higher-end devices. Now, a fix for the vulnerability is headed to Android devices. The bug&#8230;<\/p>\n","protected":false},"author":1,"featured_media":243870,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/05\/f9c530cb.png","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-243869","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/243869","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=243869"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/243869\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/243870"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=243869"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=243869"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=243869"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}