Google has resolved a critical security flaw in Android 12 with its February 2022 Android security update.
The vulnerability, code-named CVE-2021-39675, affected the System component and could allow hackers to gain admin privileges remotely.
Google's Android Security Bulletin also addresses a second critical vulnerability, CVE-2021-30317, which affects a closed-source component built by Qualcomm and was active on all Android devices fitted with the hardware.
Vulnerability and patch management
Keep known vulnerabilities out of your IT infrastructure
Thus far, there have been no reports of active exploitation of either of the now-patched vulnerabilities.
Aside from CVE-2021-39675 and CVE-2021-30317 vulnerabilities, Google issued fixes for five high-severity flaws in Framework, four high-severity bugs in Media Framework, seven high-severity to critical flaws in System, two vulnerabilities of unknown severity in Media Provider, one high-severity flaw in Amlogic components, five high-severity bugs in MediaTek components, three high-severity flaws in Unisoc components, and six high to critical severity vulnerabilities in Qualcomm components.
“The severity assessment of bugs is based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed,” explained Google.
However, the search giant noted that the severity of vulnerabilities affecting Amlogic, MediaTek, Unisoc, and Qualcomm components are determined by the source vendor.
Google Play system updates and security updates are available for Android devices running Android 10 and later.
Get the ITPro. daily newsletter
Receive our latest news, industry updates, featured resources and more. Sign up today to receive our FREE report on AI cyber crime & security - newly updated for 2023.