數百萬台Android設備存安全漏洞谷歌花了數月修復
手機開發者論壇XDA今日透露,谷歌已修復有關Android設備的一個嚴重安全漏洞,其涉及數百萬台使用聯發科芯片組的Android設備。據悉該漏洞公開已經有數月時間,是一個存在於CPU固件中的後門。
XDA表示,該漏洞使得惡意程序通過簡單腳本就可獲得使用聯發科64位芯片的Android設備訪問權限,因此會影響到數百種智能手機、平板電腦和智能機頂盒。
谷歌在3月份的Android安全公告中提到了相應補丁(CVE-2020-0069),此前有關該漏洞的細節已經在網上流傳了數月。值得注意的是,黑客仍可在數十種Android設備上利用該漏洞。
利用該漏洞的黑客可以通過多種方式造成損害,其可以安裝應用程序,然後授予其入侵設備所需的任何權限。黑客也可利用漏洞中的Root權限啟動勒索軟件,可能使整個設備無法使用。
自2019年5月以來,聯發科已經提供修復這一漏洞的補丁,但該公司不能強迫原始設備製造商修復設備。XDA解釋說,而谷歌可以通過許可協議和相應條款修復設備。據XDA稱,谷歌在發布補丁前幾個月就知曉這一漏洞。
受影響設備清單:
- Acer Iconia One 10 B3-A30
- Acer Iconia One 10 B3-A40
- Alba tablet series
- Alcatel 1 5033 series
- Alcatel 1C
- Alcatel 3L (2018) 5034 series
- Alcatel 3T 8
- Alcatel A5 LED 5085 series
- Alcatel A30 5049 series
- Alcatel Idol 5
- Alcatel/TCL A1 A501DL
- Alcatel/TCL LX A502DL
- Alcatel Tetra 5041C
- Amazon Fire 7 2019 — up to Fire OS 6.3.1.2 build 0002517050244 only
- Amazon Fire HD 8 2016 — up to Fire OS 5.3.6.4 build 626533320 only
- Amazon Fire HD 8 2017 — up to Fire OS 5.6.4.0 build 636558520 only
- Amazon Fire HD 8 2018 — up to Fire OS 6.3.0.1 only
- Amazon Fire HD 10 2017 — up to Fire OS 5.6.4.0 build 636558520 only
- Amazon Fire HD 10 2019 — up to Fire OS 7.3.1.0 only
- Amazon Fire TV 2 — up to Fire OS 5.2.6.9 only
- ASUS ZenFone Max Plus X018D
- ASUS ZenPad 3s 10 Z500M
- ASUS ZenPad Z3xxM(F) MT8163-based series
- Barnes & Noble NOOK Tablet 7″ BNTV450 & BNTV460
- Barnes & Noble NOOK Tablet 10.1″ BNTV650
- Blackview A8 Max
- Blackview BV9600 Pro (Helio P60)
- BLU Life Max
- BLU Life One X
- BLU R1 series
- BLU R2 LTE
- BLU S1
- BLU Tank Xtreme Pro
- BLU vivo 8L
- BLU Vivo XI
- BLU Vivo XL4
- Bluboo S8
- BQ Aquaris M8
- CAT S41
- Coolpad Cool Play 8 Lite
- Dragon Touch K10
- Echo Feeling
- Gionee M7
- HiSense Infinity H12 Lite
- Huawei GR3 TAG-L21
- Huawei Y5II
- Huawei Y6II MT6735 series
- Lava Iris 88S
- Lenovo C2 series
- Lenovo Tab E8
- Lenovo Tab2 A10-70F
- LG K8+ (2018) X210ULMA (MTK)
- LG K10 (2017)
- LG Tribute Dynasty
- LG X power 2/M320 series (MTK)
- LG Xpression Plus 2/K40 LMX420 series
- Lumigon T3
- Meizu M5c
- Meizu M6
- Meizu Pro 7 Plus
- Nokia 1
- Nokia 1 Plus
- Nokia 3
- Nokia 3.1
- Nokia 3.1 Plus
- Nokia 5.1
- Nokia 5.1 Plus/X5
- Onn 7″ Android tablet
- Onn 8″ & 10″ tablet series (MT8163)
- OPPO A5s
- OPPO F5 series/A73 — Android 8.x only
- OPPO F7 series — Android 8.x only
- OPPO F9 series — Android 8.x only
- Oukitel K12
- Protruly D7
- Realme 1
- Sony Xperia C4
- Sony Xperia C5 series
- Sony Xperia L1
- Sony Xperia L3
- Sony Xperia XA series
- Sony Xperia XA1 series
- Southern Telecom Smartab ST1009X (MT8167)
- TECNO Spark 3 series
- Umidigi F1 series
- Umidigi Power
- Wiko Ride
- Wiko Sunny
- Wiko View3
- Xiaomi Redmi 6/6A series
- ZTE Blade A530
- ZTE Blade D6/V6
- ZTE Quest 5 Z3351S