Google researchers have discovered a new zero-day exploit in Android that has the potential to infect millions of devices. The vulnerability lies in the core of the operating system and has already been exploited by hackers. Below you'll find the phones known to be affected, including models from Google, Samsung , and Huawei.

Project Zero is a team of Google security analysts who specialize in finding vulnerabilities. As reported by TechRadar, the latest exploit discovered by Project Zero can be used to gain root access on targeted devices.
Google's Threat Analysis Team (TAG) confirmed that the vulnerability has been used in real-world attacks. Israel-based company NSO Group has been named as the likely culprit. (NSO has denied any involvement.)
According to Project Zero, the bug is a local privilege escalation vulnerability that allows a vulnerable device to be fully compromised.
"This issue is rated as high severity on Android and in itself requires the installation of a malicious application for potential exploitation," a researcher warned.
See the smartphones known to be affected by the vulnerability:
- Google Pixel 2
- Huawei P20
- Xiaomi Redmi 5A
- Xiaomi Redmi Note 5
- Xiaomi A1
- Oppo A3
- Moto Z3
- LG phones running Android Oreo
- Samsung Galaxy S7
- Samsung Galaxy S8
- Samsung Galaxy S9
However, researchers fear that more Android smartphones could be affected, as the exploit requires little or no customization per device.
How to protect yourself
Device manufacturers have been notified by Google, so operating system updates are expected to be released soon. In the meantime, it's imperative to avoid downloading from dangerous websites or apps from sources you're not sure about. The vulnerability requires the installation of a malicious app to take control of a device - as long as you avoid the above, your phone will remain safe.
