CVE-2023-4863 was due on October 4, 2023 and CVE-2023-4211 has to be patched by October 24, 2023.
The Cybersecurity & Infrastructure Security Agency (CISA) has already added these two actively exploited vulnerabilities to its catalog of known to be exploited vulnerabilities
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
That vulnerability is patched if your phone is at patch level 2023-10-05.
But the next one isn’t. Your phone needs to be at patch level 2023-10-06 for that.
CVE-2023-4211: a local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory
this vulnerability affects multiple versions of Arm Mali GPU drivers which are used in a broad range of Android device models
including on phones developed by Google, Samsung, Huawei, and Xiaomi, as well as in some Linux devices
A GPU is a specific type of chip mostly used for graphics-related tasks, such as rendering images and videos, but also for resource-heavy calculations, such as training artificial intelligence
The higher the patch level number, the more vulnerabilities will be fixed. In this round the only difference between patch levels 2023-10-05 and 2023-10-06 is the important patch for CVE-2023-4211
@ecksmc just checked and mine is up to date
@NorthernInvader a google phone??
pixel phones will always get updates before others
mine is only at patch level 2023-10-05
CVE-2023-4863: a heap buffer overflow in libwebp which affects many applications that use this library to encode and decode images in the WebP format, allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
This is a vulnerability that impacts many applications, which malwarebytes have discussed at length in an article explaining how it was used to install spyware.
https://www.malwarebytes.com/blog/news/2023/09/pegasus-spyware-and-how-it-exploited-a-webp-vulnerability