BlackBerry have promised to deliver security patches on a monthly basis for the BlackBerry Priv, and so far they are keeping good on that promise.
Here we are on February 1 and the BlackBerry Priv February update (AAD444,) is now rolling out to Priv’s worldwide.
The update comes in at 17Gb.
The most severe of these issues is a Critical security vulnerability that could enable remote code execution on an affected device through multiple methods such as email, web browsing, and MMS when processing media files.
The Remote Code Execution Vulnerability in Broadcom’s Wi-Fi driver is also Critical severity as it could allow remote code execution on an affected device while connected to the same network as the attacker.
Security Vulnerability Summary
[table style=”table-striped”]
Issue | CVE | Severity |
---|---|---|
Remote Code Execution Vulnerability in Broadcom Wi-Fi Driver | CVE-2016-0801 CVE-2016-0802 |
Critical |
Remote Code Execution Vulnerability in Mediaserver | CVE-2016-0803 CVE-2016-0804 |
Critical |
Elevation of Privilege Vulnerability in Qualcomm Performance Module | CVE-2016-0805 | Critical |
Elevation of Privilege Vulnerability in Qualcomm Wi-Fi Driver | CVE-2016-0806 | Critical |
Elevation of Privilege Vulnerability in the Debugger Daemon | CVE-2016-0807 | Critical |
Denial of Service Vulnerability in Minikin | CVE-2016-0808 | High |
Elevation of Privilege Vulnerability in Wi-Fi | CVE-2016-0809 | High |
Elevation of Privilege Vulnerability in Mediaserver | CVE-2016-0810 | High |
Information Disclosure Vulnerability in libmediaplayerservice | CVE-2016-0811 | High |
Elevation of Privilege Vulnerability in Setup Wizard | CVE-2016-0812 CVE-2016-0813 |
Moderate |
[/table]
You can check out full details of the Security Bulletin February 2016 here.
Apart from the security update we do know that this build also brings the following improvements:
- Resolves issue where device shows bars of signal in locations with no signal.
- Resolves issue where VoLTE to VoLTE calls do not get forwarded to voicemail.
If you own a Priv and are not seeing the system update message, you can check manually by heading into Settings -> About phone -> System updates and checking manually.