In: Computer Science
Patch 1: There was a possiblility to agree to the Terms and Conditions without authentication of the user. It was of low severety threat which was reported in march 2020. The patch blocked the authentication bypass and the threat was mitigated.
Patch 2: It was made possible for any sensitive data to be leaked from Auto Hotspot mode. It was of very high threat which was reported in april 2020. The patch modified the data saving methodology of content provider to block the threat.
Patch 3: There was a case of Buffer overflow vulnerability in with the technical fault in abnormal setup message. It was a critical threat reported in june 2020 and was privately disclosed. It was caused due to buffer overflow in baseband which allowed random code execution in exynos chip mobile devices of samsung. the patch included the validation check for buffer length before write into buffer to check the overflow.
List of software vendors and number of vulnerabilities fixed by patches and security updates:
Vendors/ Software publisher | Patches fixed |
Adobe | 2052 |
Microsoft | 2143 |
1040 | |
Apple | 968 |
Cisco | 388 |
Oracle | 568 |
Reference: Syxsense.com