Black Hat is coming and with it a good reason to update your "Broadcom-based" devices, (Fri, Jul 21st)

Black Hat US 2017 is debuting and with it a potential concern to most of us. It turns out that one of the conference presentations, entitledBROADPWN: REMOTELY COMPROMISING ANDROID AND IOS VIA A BUG IN BROADCOMS WI-FI CHIPSETS[1],will detail how Broadcom BCM43xx Wi-Fi chipsets can be exploited to achieve full code execution on the compromised device without user interaction.

An attacker within range may be able to execute arbitrary code on the Wi-Fi chip, says Apple about this vulnerability (CVE-20179417) in its latest security bulletin [2]. Google published the patch to fix the vulnerability on Android early this month [3].

Besides Apple, those chipsets are present on most smartphone devices like HTC, LG, Nexus and most Samsumg models as well. Make sure to have this vulnerability fixed in all your devices??especially if you are planning to be in Las Vegas next week.

References
[1]https://www.blackhat.com/us-17/briefings.html#broadpwn-remotely-compromising-android-and-ios-via-a-bug-in-broadcoms-wi-fi-chipsets
[2]https://support.apple.com/pt-br/HT207923
[3]https://source.android.com/security/bulletin/2017-07-01

--
Renato Marinho
Morphus Labs| LinkedIn|Twitter

© SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Article Link: https://isc.sans.edu/diary/rss/22638