Google has recently rolled out a patch to address three high-severity vulnerabilities in Android, including one reportedly exploited in the wild. As these flaws impact some of the most recent versions of the popular mobile operating system, businesses should promptly patch their endpoints. In its April 2023 Android security bulletin, Google detailed the flaws tracked as CVE-2023-21085, CVE-2023-21096, and CVE-2022-38181.
Affected versions and recommendations
The first two vulnerabilities, CVE-2023-21085 and CVE-2023-21096, affect the Android System and allow for remote code execution. Experts believe that attackers could exploit these vulnerabilities through phishing. Hackers have reportedly exploited the third vulnerability, CVE-2022-38181, a flaw in the Arm Mali GPU kernel driver, since late last year. This use-after-free vulnerability lets threat actors escalate privileges on targeted endpoints by using malicious apps.
Google did not disclose who exploited these flaws, against whom, or for what purposes. Android 11, Android 12, Android 12L, and Android 13 are all affected, and users should apply the fix immediately. To update your device, go to the Settings menu, scroll to the About Phone section, and find the menu item that allows you to check for software updates.
Due to the decentralized nature of Google’s mobile ecosystem, different manufacturers may take varying amounts of time to release the Android security patch. If your device does not yet have the patch available, expect one to address these critical vulnerabilities in the coming days or weeks.
Meanwhile, think about installing an Android antivirus app to provide extra protection against malware and similar vulnerabilities. Make sure to enable Google Play Protect, as it acts as Android’s default antivirus app and typically comes pre-installed.
It is crucial to stay informed about security updates and vulnerabilities, as cybercriminals are constantly looking for new ways to exploit devices. Regularly updating your Android device, installing a reliable antivirus app, and practicing safe online habits will help reduce the risk of being targeted. In addition, be cautious about downloading apps from unknown sources and avoid clicking on suspicious links. By taking these precautionary measures, users can further protect their devices and personal information from potential threats while awaiting the latest security updates.