In its recent monthly security update, Google has addressed a critical vulnerability affecting numerous Android devices, as well as some iPhone models. This vulnerability, known as BroadPwn, involves a severe flaw in certain Broadcom Wi-Fi chipsets that could allow attackers to execute malicious code remotely without requiring any user interaction.
The BroadPwn vulnerability is a remote code execution issue affecting the BCM43xx family of Wi-Fi chipsets. Exploitation of this flaw can grant attackers kernel-level privileges on compromised devices. Further elaborating on the matter, Google stated in the July 2017 Android Security Bulletin, “The most severe vulnerability in this [runtime] section could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process.”
Identified by Exodus Intelligence researcher Nitay Artenstein, the BroadPwn vulnerability (CVE-2017-3544) has significant implications beyond Android devices, as it also affects Apple iOS devices. This situation raises concerns among businesses that depend on these platforms for their operations.
The vulnerability affects a wide range of mobile devices, which includes various models of iPhones and leading Android manufacturers, including HTC, LG, Nexus, and Samsung. The widespread nature of this flaw further illustrates the potential risk faced by both personal and enterprise environments.
While Google has implemented fixes for the BroadPwn vulnerability, the July Android Security Bulletin includes a total of ten critical patches, all related to remote code execution, alongside 94 high and 32 moderate vulnerabilities. Due to the rapid adoption of these updates, devices specifically from Google’s Pixel and Nexus lines have begun receiving necessary firmware updates. However, other Android devices will need to rely on their respective Original Equipment Manufacturers (OEMs) for similar protections, leaving millions vulnerable until these updates are released.
This vulnerability is not an isolated incident. Previously, an over-the-air hijacking vulnerability affecting Broadcom Wi-Fi SoC chips was discovered, which allowed attackers on the same network to compromise iOS and Android devices without user interaction. Following that, Apple swiftly published an emergency patch, and Google addressed the issue within its April 2017 security updates.
As businesses evaluate their cybersecurity posture, it is essential to acknowledge the potential MITRE ATT&CK tactics related to the BroadPwn vulnerability. Techniques that may have been exploited include initial access through network intrusion and privilege escalation once access has been gained. With such vulnerabilities requiring immediate attention, businesses must remain vigilant and prioritize timely updates to safeguard their digital ecosystems.
In summary, the recent disclosures around BroadPwn underline a pressing cybersecurity concern for users of both Android and iOS devices. Given the broad impact of this vulnerability, organizations should be proactive in monitoring updates and assessing their exposure to similar threats.