Google’s Threat Analysis Group researchers warn of a Samsung zero-day vulnerability that is actively exploited in the wild.
The vulnerability tracked as CVE-2024-44068 (CVSS score of 8.1) is a use-after-free issue, which could be exploited to escalate privileges on a vulnerable Android device.
A vulnerability resides in Samsung mobile processors and according to the experts, it has been chained with other vulnerabilities to achieve arbitrary code execution on vulnerable devices.
Samsung addressed the vulnerability with the release of security updates in October 2024.
The affected versions include Exynos 9820, 9825, 980, 990, 850, W920.
The vulnerability was discovered by the researchers Xingyu Jin from Google Devices & Services Security Research and Clement Lecigene from Google Threat Analysis Group.
Google TAG discovering the flaw suggests that commercial spyware vendors may have used the exploit to target Samsung devices.
The advisory published by Google Project Zero warns of the availability of a zero-day exploit that is part of an Eòlevation of Privilege chain.
Google researchers reported that the vulnerability resides in a driver that provides hardware acceleration for media functions and which maps userspace pages to I/O pages, executes a firmware command, and tears down mapped I/O pages..
While the researchers have not provided details on the observed attacks, Google TAG often discloses zero-days exploited by spyware vendors, including against Samsung devices.
Image Credits : Themobileindian

















Comments