Hackers are exploiting a zero-day vulnerability in Google 's Android operating system that could give them complete control over at least 18 different phone models, including four different Pixel models, a member of Google's Project Zero research team recently said

There is evidence that the vulnerability is being actively exploited, either by NSO Group or one of the company's customers, Maddie Stone, a Project Zero member, said in a blog post. The exploits require little or no customization to fully root vulnerable phones. The vulnerability can be exploited in two ways: (1) when a target installs an untrusted app or (2) for web-based attacks, combining two exploits targeting a vulnerability in the code.
The list of vulnerable smartphones, so far:
- Pixel 1
- Pixel 1 XL
- Pixel 2
- Pixel 2 XL
- Huawei P20
- Xiaomi Redmi 5A
- Xiaomi Redmi Note 5
- Xiaomi A1
- Oppo A3
- Moto Z3
- Oreo LG phones
- Samsung S7
- Samsung S8
- Samsung S9
Google announced that the vulnerability will be fixed immediately with the October Android security update which will be released in a few days.

It is worth noting that the vulnerability was first discovered in the Linux kernel and was patched in early 2018 in version 4.14. This update was incorporated into versions 3.18, 4.4 and 4.9 of the Android kernel. For reasons that were not explained, these patches were never included in Android security updates. Thanks to this, we can understand why older Pixel models are vulnerable while newer versions are not. The flaw is now tracked as CVE-2019-2215.
