CheckPoint Finds An RCE Vulnerability Affecting Millions of Devices



Israel-based cyber security company CheckPointdiscovered a vulnerability that could allow code execution on millions of devices.

CheckPoint researchers According to the details he shared with The Hacker News These vulnerabilities, located in the RCE (Remote Code Execution) type, allow attackers to access data without the need to execute any malware on their targets.

In addition, the privileges of Android applications running with low rights can be upgraded.

ALLHACK vulnerabilities caused by the open source lossless audio codec called ALAC (Apple Lossless Audio Codec), developed by Apple in 2011, are used by Qualcomm and MediaTek.



While the vulnerabilities in the proprietary versions of ALAC are constantly being patched by Apple, the open source version used by the chip manufacturers does not seem to have been updated since 2011.

According to CheckPoint’s post Two of the vulnerabilities affect MediaTek and one affects Qualcomm chips.

  • CVE-2021-0674 (MediaTek): Information disclosure on ALAC codecs without any user intervention
  • CVE-2021-0675 (MediaTek): LPE vulnerability using ALAC codecs
  • CVE-2021-30351 (Qualcomm): Out-of bound memory access vulnerability caused by incorrect validation during audio playback

While these vulnerabilities were reported to be patched by CheckPoint in December 2021, Qualcomm and MediaTek have already released security updates for the devices.

Those who have not yet updated their devices at the moment do not need to do anything else to close the gap, except to apply software updates.



Related News

The first MacBook Pro with M2 are already reaching their users

On June 6, Apple announced that some MacBook Pro models would incorporate the new M2 chip, which guarantees that the interior of these computers will be

Why your e-mail is becoming more and more dangerous

No doubt the email It is something we use constantly. We use it to be in contact with other people or with companies, but also to simply be able to register

Google says Apple and Android phones have been hacked by Italian spyware. hacking

Alphabet Inc's Google said in a new report that hacking tools from an Italian company were used to spy on Apple and Android smartphones in Italy and Kazakhstan.

Google says Slice payments app spies photos, audio records and call history

Fintech company Slice, which has introduced itself as an alternative to credit cards, has come under scrutiny after Google alerted users that the app was

This Premium Wear OS 3 Smartwatch Beats the Pixel Watch, But I Won’t Buy It

While I was expecting to see brand new smartwatches running Wear OS 3 in the coming months, I wasn't expecting them as soon as July, and I'm certainly looking