Skip to main content

Android Vulnerabilities

Thirty three vulnerabilities have been identified in Google’s Android mobile operating system (OS), the most severe of which allows remote code execution (RCE) in the context of the application.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Thirty three vulnerabilities have been identified in Google’s Android mobile operating system (OS), the most severe of which allows remote code execution (RCE) in the context of the application.

Affected platforms

The following platforms are known to be affected:

Threat details

Depending on the privileges afforded to the application, an attacker is able to install programs; view, create, modify or delete data; or create new privileged accounts. Exploitation would have significantly less impact on devices configured with fewer user rights on the system than those configured with administrative rights.

Eight vulnerabilities received a critical rating. These vulnerabilities include remote code execution, privilege escalation and information disclosure.

CVEs


Remediation steps

Type Step
  • Run all software as a non-privileged user to diminish the impact of a successful attack.
  • Remind users to download apps only from trusted vendors in the Play Store.
  • Remind users not to visit untrusted websites or follow links provided by unknown or untrusted sources.
  • Inform and educate users regarding the threats posed by hypertext links contained in emails or attachments especially from untrusted sources.


Last edited: 17 February 2020 11:26 am