Google fixes 40 security bugs, 8 rated as critical

Jun 6, 2016 21:05 GMT  ·  By

Google released the details for June's Android Security Bulletin, and the company fixed 40 security bugs in its mobile OS, of which eight were labeled as Critical, the highest severity rating.

As always, the Mediaserver component received the most security fixes, with patches for one remote code execution issue, twelve fixes for various elevation of privilege vulnerabilities, one fix for an information disclosure issue, and one for a denial of service vulnerability.

This component plays a crucial role in Android devices, being the one tasked with handling multimedia elements on the phone.

Exploitation of security weaknesses in the Mediaserver component is trivial since attackers only need to send an MMS or fool the user into accessing a Web page hosting corrupted media files.

Second to the Mediaserver component, Google also fixed a large number of bugs in Qualcomm components. The Qualcomm Camera, Video, Sound, GPU, and Wi-Fi drivers are received multiple fixes, fifteen in total, taking up a third of the entire security bulletin.

The Broadcom Wi-Fi driver, the MediaTek Power Management driver, and the NVIDIA Camera drivers also received fixes, but none were rated as severe.

Most severe bugs

Of the eight bugs that did warrant a "Critical" rating, six would have led to a permanent device compromise, which Google says could have been fixed only if the user reinstalled his Android operating system.

All these six bugs were in Qualcomm components. Qualcomm bugs should not be underestimated, as proven by a report from two weeks ago when one single Qualcomm bug affected nearly two-thirds of all Android devices.

The other two Critical bugs were in the Mediaserver component, and in the libwebm library, which is also part of the bigger Mediaserver module.

Security updates for Nexus devices were released as over-the-air updates, while OEMs will have to wait for updated OS images for at least two more days before implementing this month's fixes in their own OS update packages.

Thank-yous for this month's security fixes need to be addressed to Android's own security team and Google's Project Zero, but also to companies that submitted bug reports, such as Alibaba, Tencent, CORE Team, Qihoo 360, and a slew of independent researchers. Below is a table detailing all security bugs.  

Issue CVE Severity Affects Nexus?
Remote Code Execution Vulnerability in Mediaserver CVE-2016-2463 Critical Yes
Remote Code Execution Vulnerabilities in libwebm CVE-2016-2464 Critical Yes
Elevation of Privilege Vulnerability in Qualcomm Video Driver CVE-2016-2465 Critical Yes
Elevation of Privilege Vulnerability in Qualcomm Sound Driver CVE-2016-2466
CVE-2016-2467
Critical Yes
Elevation of Privilege Vulnerability in Qualcomm GPU Driver CVE-2016-2468
CVE-2016-2062
Critical Yes
Elevation of Privilege Vulnerability in Qualcomm Wi-Fi Driver CVE-2016-2474 Critical Yes
Elevation of Privilege Vulnerability in Broadcom Wi-Fi Driver CVE-2016-2475 High Yes
Elevation of Privilege Vulnerability in Qualcomm Sound Driver CVE-2016-2066
CVE-2016-2469
High Yes
Elevation of Privilege Vulnerability in Mediaserver CVE-2016-2476
CVE-2016-2477
CVE-2016-2478
CVE-2016-2479
CVE-2016-2480
CVE-2016-2481
CVE-2016-2482
CVE-2016-2483
CVE-2016-2484
CVE-2016-2485
CVE-2016-2486
CVE-2016-2487
High Yes
Elevation of Privilege Vulnerability in Qualcomm Camera Driver CVE-2016-2061
CVE-2016-2488
High Yes
Elevation of Privilege Vulnerability in Qualcomm Video Driver CVE-2016-2489 High Yes
Elevation of Privilege Vulnerability in NVIDIA Camera Driver CVE-2016-2490
CVE-2016-2491
High Yes
Elevation of Privilege Vulnerability in Qualcomm Wi-Fi Driver CVE-2016-2470
CVE-2016-2471
CVE-2016-2472
CVE-2016-2473
High Yes
Elevation of Privilege Vulnerability in MediaTek Power Management Driver CVE-2016-2492 High Yes
Elevation of Privilege Vulnerability in SD Card Emulation Layer CVE-2016-2494 High Yes
Elevation of Privilege Vulnerability in Broadcom Wi-Fi Driver CVE-2016-2493 High Yes
Remote Denial of Service Vulnerability in Mediaserver CVE-2016-2495 High Yes
Elevation of Privilege Vulnerability in Framework UI CVE-2016-2496 Moderate Yes
Information Disclosure Vulnerability in Qualcomm Wi-Fi Driver CVE-2016-2498 Moderate Yes
Information Disclosure Vulnerability in Mediaserver CVE-2016-2499 Moderate Yes
Information Disclosure Vulnerability in Activity Manager CVE-2016-2500 Moderate Yes