Live Now

Google's April Android Security Update Fixes 8 Critical Vulnerabilities

Advertisement
By Ketan Pratap | Updated: 5 April 2016 12:29 IST
Google's April Android Security Update Fixes 8 Critical Vulnerabilities
Google on Monday started rolling out the April monthly Android security update for its Nexus range of devices. The company says that the security update is now available for Nexus devices through an over-the-air (OTA) update.

The latest Nexus firmware images have also been released to the Google Developer site for download as well as changelogs have been published on the Android Open Source Project (AOSP) for its partners and other manufacturers. Google says that the source code patches for these issues will be released to the Android Open Source Project (AOSP) repository over the next 48 hours. While other manufacturers prepare to release their device-specific updates, BlackBerry has already released the April security update for its Priv Android smartphone.

The latest April update patches eight vulnerabilities that have been flagged as "critical" by Google, and 13 vulnerabilities that fall on the spectrum of "high" severity. The company has also listed eight "moderate" security glitches that have also been resolved.

In its Nexus Security Bulletin for April, Google said the Android security update has fixed one of the most severe Stagefright security vulnerabilities that could enable remote code execution on an affected device through multiple methods (such as email, Web browsing, and MMS) when processing media files. The Bulletin notes that partner OEMs were notified about the issues described in the April security update on March 16, 2016 or earlier.

The critical security vulnerabilities fixed in the update by Google include remote code execution vulnerability in DHCPCD, which if left untreated can enable attacker to cause memory corruption. Other vulnerabilities such as remote code execution vulnerability in media codec, remote code execution vulnerability in mediaserver, and remote code execution vulnerability in libstagefright can allow an attacker to cause memory corruption and remote code execution as the mediaserver process during media file and data processing of a specially crafted file.

Advertisement

Some of the other critical vulnerabilities listed include elevation of privilege vulnerability in kernel, elevation of privilege vulnerability in Qualcomm Performance Module, elevation of Privilege Vulnerability in Qualcomm RF Component, and elevation of Privilege Vulnerability in Kernel.

Notably, the majority of vulnerabilities fixed in the April Android security update were reported to Google late last year or early this year.

Advertisement

Much like the February and March security updates, the April Android security update is purely focused on security fixes and does not upgrade the Android version.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Pad 3 With Snapdragon 8 Elite SoC to Launch Globally on This Date
  2. Google I/O 2025 LIVE: AI Expected to Dominate Google's Showcase
  3. iQOO Neo 10 Pro+ With Snapdragon 8 Elite, 6,800mAh Battery Launched
  4. Infinix Hot 60 Pro+ Tipped to Debut as the Slimmest Curved Screen Phone
  5. Nothing Phone 3 Confirmed to Launch Globally in July
  6. Infinix XPad GT Will Debut on May 21 With This Snapdragon Chip
  7. Realme Partners With Aston Martin for Realme GT 7 Dream Edition
  8. OnePlus Ace 5 Racing Edition, Ace 5 Ultra to Launch on This Date
  1. US DoJ Said to Open Probe Into Coinbase Data Breach, Firm Claims Involvement of Indian Employees
  2. Supreme Court Questions Lack of Crypto Regulatory Measures, Oversight: Report
  3. iQOO Neo 10 Pro+ With Snapdragon 8 Elite, 6,800mAh Battery Launched: Price, Specifications
  4. MediaTek Showcases AI Strategy At Computex 2025, Unveils Hybrid Computing Solution
  5. Vi Postpaid International Roaming Plans Now Offer Double Data, Travel Security Benefits and More
  6. Nintendo Turns to Samsung to Make Chips, Ramp Up Switch 2 Output
  7. Redmi Pad 2 Renders Price Leaked; Said to Feature MediaTek Helio G100 Ultra Chip, 9,000mAh Battery
  8. Microsoft Is Bringing Elon Musk’s AI Models to Its Cloud
  9. Intel Arc Pro B-Series GPUs With XMX AI Cores and Advanced Ray Tracing Units Launched
  10. Microsoft NLWeb Open Project for AI-Powered Natural Language Interface for Websites Unveiled
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.