CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Information Security

Critical UNISOC Chip Vulnerability Affects Millions of Android Smartphones

admin by admin
June 6, 2022
in Information Security
Share on FacebookShare on Twitter


A critical security flaw has been uncovered in UNISOC’s smartphone chipset that could be potentially weaponized to disrupt a smartphone’s radio communications through a malformed packet.

“Left unpatched, a hacker or a military unit can leverage such a vulnerability to neutralize communications in a specific location,” Israeli cybersecurity company Check Point said in a report shared with The Hacker News. “The vulnerability is in the modem firmware, not in the Android OS itself.”

UNISOC, a semiconductor company based in Shanghai, is the world’s fourth-largest mobile processor manufacturer after Mediatek, Qualcomm, and Apple, accounting for 10% of all SoC shipments in Q3 2021, according to Counterpoint Research.

CyberSecurity

The now-patched issue has been assigned the identifier CVE-2022-20210 and is rated 9.4 out of 10 for severity on the CVSS vulnerability scoring system.

In a nutshell, the vulnerability — discovered following a reverse-engineering of UNISOC’s LTE protocol stack implementation — relates to a case of buffer overflow vulnerability in the component that handles Non-Access Stratum (NAS) messages in the modem firmware, resulting in denial-of-service.

CyberSecurity

To mitigate the risk, it’s recommended that users update their Android devices to the latest available software as and when it becomes available as part of Google’s Android Security Bulletin for June 2022.

“An attacker could have used a radio station to send a malformed packet that would reset the modem, depriving the user of the possibility of communication,” Check Point’s Slava Makkaveev said.

This isn’t the first time UNISOC chipsets have come under the scanner. In March 2022, mobile security firm Kryptowire disclosed a critical security flaw (CVE-2022-27250, CVSS score: 9.8) that, if exploited, could allow malicious actors to take control over user data and device functionality





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
Previous Post

Scammers Target NFT Discord Channel

Next Post

The CIO plays a key role as the connective tissue of the organization with Mark Grimse

Related Posts

Information Security

Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

by admin
June 24, 2022
Information Security

ToddyCat claws at Asian governments

by admin
June 24, 2022
Information Security

NSO Confirms Pegasus Spyware Used by at least 5 European Countries

by admin
June 23, 2022
Information Security

AWS re:Inforce 2022: Threat detection and incident response track preview

by admin
June 23, 2022
Information Security

Vishing scams on the rise: How to protect yourself

by admin
June 23, 2022
Next Post

The CIO plays a key role as the connective tissue of the organization with Mark Grimse

Leave Comment

Recommended

“We Need to Get Better”: How CIOs Are Working to Extract More Value from EHRs

June 25, 2022

Innerframeworkforblance

June 25, 2022

Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

June 24, 2022

ToddyCat claws at Asian governments

June 24, 2022

“People Are What Makes Tech Work”: Lee Milligan Reflects on His Journey at Asante

June 24, 2022

Innercapabiltyconnectivity

June 24, 2022

© 2022 CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 JNews - Premium WordPress news & magazine theme by Jegtheme.