Hem
(Martina Holmberg / TT)

Google kritiserar långsamma säkerhetsuppdateringar

Googles cyberhotsgrupp Threat Analysis Group kritiserar i en färsk rapport utvecklare som är långsamma med att rulla ut säkerhetsuppdateringar som åtgärdar så kallade nolldagarssårbarheter. Det rapporterar Mobil.se.

Google tar bland annat upp problem med koppling till Android och de olika skräddarsydda versioner av operativsystemet som finns. Ett av exemplen rör en sårbarhet i Samsungs egen webbläsare som upptäcktes i början av 2022, men som åtgärdades först i juni i år.

Google skriver att utvecklarna också bör lägga ned ett större arbete med att analysera säkerhetsbristerna. 40 av de nolldagarssårbarheter som identifieras är enligt Google varianter av tidigare rapporterade sårbarheter.

 
Nolldagarssårbarheter (Zero-day)
Wikipedia (en)
A zero-day (also known as a 0-day) is a computer-software vulnerability previously unknown to those who should be interested in its mitigation, like the vendor of the target software. Until the vulnerability is mitigated, hackers can exploit it to adversely affect programs, data, additional computers or a network. An exploit taking advantage of a zero-day is called a zero-day exploit, or zero-day attack. The term "zero-day" originally referred to the number of days since a new piece of software was released to the public, so "zero-day software" was obtained by hacking into a developer's computer before release. Eventually the term was applied to the vulnerabilities that allowed this hacking, and to the number of days that the vendor has had to fix them. Once the vendors learn of the vulnerability, they will usually create patches or advise workarounds to mitigate it. The more recently that the vendor has become aware of the vulnerability, the more likely it is that no fix or mitigation has been developed. Once a fix is developed, the chance of the exploit succeeding decreases as more users apply the fix over time. For zero-day exploits, unless the vulnerability is inadvertently fixed, such as by an unrelated update that happens to fix the vulnerability, the probability that a user has applied a vendor-supplied patch that fixes the problem is zero, so the exploit would remain available. Zero-day attacks are a severe threat.
Omni är politiskt obundna och oberoende. Vi strävar efter att ge fler perspektiv på nyheterna. Har du frågor eller synpunkter kring vår rapportering? Kontakta redaktionen