Samsung's Exynos Processors Vulnerable to Privilege Escalation Due to Use-After-Free Bug

CVE-2024-44068
Currently unrated 🤨

Key Information

Vendor
Samsung
Vendor
CVE Published:
7 October 2024

Badges

đź‘ľ Exploit Existsđź“° News Worthy

Summary

A zero-day vulnerability in Samsung's mobile processors, tracked as CVE-2024-44068, has been exploited in the wild to execute an arbitrary code. This vulnerability, with a CVSS score of 8.1, allows privilege escalation on vulnerable Android devices by leveraging a use-after-free bug in the m2m scaler driver. The bug is part of an exploit chain, and the in-the-wild exploit has been observed by Google's Threat Analysis Group, posing a significant risk to affected devices. The exploitation has been observed in a privileged cameraserver process through a Kernel Space Mirroring Attack, bypassing Android kernel isolation protections. Samsung has released a patch as part of its October 2024 security updates.

News Articles

Timeline

  • đź‘ľ

    Exploit exists.

  • First article discovered by SecurityWeek

  • Vulnerability published.

Collectors

NVD Database11 News Article(s)
.