Google opublikowało grudniowy biuletyn bezpieczeństwa systemu Android, w którym zamieszczono poprawki do 40 podatności tego systemu, w tym 2 krytyczne.

CVE Severity Updated AOSP versions
Framework
CVE-2020-0001 Moderate 10
High 8.0, 8.1, 9
CVE-2020-0003 High 8.0
CVE-2020-0004 High 8.0, 8.1, 9, 10
Media framework
CVE-2020-0002 Moderate 10
Critical 8.0, 8.1, 9
System
CVE-2020-0006 High 8.0, 8.1, 9, 10
CVE-2020-0007 High 8.0, 8.1, 9, 10
CVE-2020-0008 High 8.0, 8.1, 9, 10
CVE Severity Component
Kernel components
CVE-2019-17666 Critical Realtek rtlwifi driver
CVE-2018-20856 High Kernel
CVE-2019-15214 High Sound subsystem
CVE-2020-0009 High ashmem
Qualcomm components
CVE-2018-11843 High WLAN host
CVE-2019-10558 High Kernel
CVE-2019-10581 High Audio
CVE-2019-10585 High Kernel
CVE-2019-10602 High Display
CVE-2019-10606 High Kernel
CVE-2019-14010 High Audio
CVE-2019-14023 High Kernel
CVE-2019-14024 High NFC
CVE-2019-14034 High Camera
CVE-2019-14036 High WLAN host
Qualcomm closed-source components
CVE-2019-2267 High Closed-source component
CVE-2019-10548 High Closed-source component
CVE-2019-10532 High Closed-source component
CVE-2019-10578 High Closed-source component
CVE-2019-10579 High Closed-source component
CVE-2019-10582 High Closed-source component
CVE-2019-10583 High Closed-source component
CVE-2019-10611 High Closed-source component
CVE-2019-14002 High Closed-source component
CVE-2019-14003 High Closed-source component
CVE-2019-14004 High Closed-source component
CVE-2019-14005 High Closed-source component
CVE-2019-14006 High Closed-source component
CVE-2019-14008 High Closed-source component
CVE-2019-14013 High Closed-source component
CVE-2019-14014 High Closed-source component
CVE-2019-14016 High Closed-source component
CVE-2019-14017 High Closed-source component

CERT PSE zachęca do zapoznania się z styczniowym biuletynem bezpieczeństwa Google Android i stosowanie aktualizacji dostarczanych przez poszczególnych producentów urządzeń.