By continuing to use the site or forum, you agree to the use of cookies, find out more by reading our GDPR policy

Broadcom WiFi chipset drivers have been found to contain vulnerabilities impacting multiple operating systems and allowing potential attackers to remotely execute arbitrary code and to trigger denial-of-service according to a DHS/CISA alert and a CERT/CC vulnerability note. Quarkslab's intern Hugues Anguelkov was the one who reported five vulnerabilities he found in the "Broadcom wl driver and the open-source brcmfmac driver for Broadcom WiFi chipsets" while reversing engineering and fuzzing Broadcom WiFi chips firmware. As he discovered, "The Broadcom wl driver is vulnerable to two heap buffer overflows, and the open-source brcmfmac driver is vulnerable to a frame validation bypass and a heap buffer overflow." The Common Weakness Enumeration database describes heap buffer overflows in the CWE-122 entry, stating that they can lead to system crashes or the impacted software going into an infinite loop, while also allowing attackers "to execute arbitrary code, which is usually outside the scope of a program's implicit security policy" and bypassing security services. As the CERT/CC vulnerability note written by Trent Novelly explains, potential remote and unauthenticated attackers could exploit the Broadcom WiFi chipset driver vulnerabilities by sending maliciously-crafted WiFi packets to execute arbitrary code on vulnerable machines. However, as further detailed by Novelly, "More typically, these vulnerabilities will result in denial-of-service attacks." Learn more by visiting OUR FORUM.

Chipmaker Intel has announced today that it will be canceling production of its 5G modems. Stating that they aim to focus on PC, ‘Internet of Things’ devices, and data focussed devices, however, they intend to make components to help improve 5G infrastructure. This comes just hours after Qualcomm announced a 6-year partnership with Apple. In his statement, Intel CEO Bob Swan made it clear that there was ‘no path to profitability and positive returns’ when talking about the smartphone modem business. Swan went on to mention that “5G continues to be a strategic priority across Intel”. This comes just two weeks after Intel rebuffed a report suggesting the company was struggling with its 5G modem program. A similar situation occurred in 2018 when it was suggested the manufacturer was having troubles with its XMM 8060 Modem, the predecessor to the 8160 that was canceled today. Intel went on to say they would provide additional details on April 25, following their Q1 2019 earnings report. Swan closes out his statement saying “[the Intel] team has developed a valuable portfolio of wireless products and intellectual property. We are assessing our options to realize the value we have created, including the opportunities in a wide variety of data-centric platforms and devices in a 5G world.” current speculation suggests the company may be looking to sell its portfolio of products. Follow this and more on OUR FORUM.

E3, also known as ‘The Electronic Entertainment Expo’ and ‘one of the hottest gaming events out there’, is just under 2 months away. Microsoft has announced their intentions for the event, and it’s looking pretty good. Will Tuttle, Xbox Wire Editor in Chief, says that this will be Microsoft’s ‘biggest E3 presence ever’ and that there’s ‘something for everyone’. The annual Xbox E3 2019 Briefing is up first, on June 9th. The briefing will encompass everything from reveal trailers for unannounced titles that are due out in 2019 to in-depth looks at previous games. You can watch it live on Sunday, June 9th, at 1 pm PDT/4PM EDT on the official Xbox Mixer Channel or on the Mixer app for Xbox One and Windows 10. The Xbox E3 2019 Briefing will also be offered in six different languages on Mixer: English, German, French, Italian, Spanish (LATAM), and Portuguese (LATAM). There are also English closed captions for those who want or need them! Inside Xbox will also be airing a special episode during E3. Inside Xbox: Live @ E3 will air on Monday, June 10th, at 3 pm PDT/6PM EDT. It’ll feature a live stream of exclusive announcements, game demos, interviews, and more. If you’re lucky enough to be attending E3 in person, Microsoft has plenty of opportunities for you too! The Microsoft Theater and Xbox Plaza at LA Live will be their base for all activities during the week. Xbox Experience will be returning to the Microsoft Theater and it’ll be open from Tuesday to Thursday. There are over 100 gameplay stations on the main stage and a ginormous Xbox merchandise shop.Learn more by visiting OUR FORUM.