HomeSecurityZero-Day vulnerabilities in Google Pixel exploited by criminal organizations

Zero-Day vulnerabilities in Google Pixel exploited by criminal organizations

Google announced that two Android security vulnerabilities affecting its Pixel smartphones have been exploited by criminal groups.

google pixel

The critical zero-day vulnerabilities are as follows:

CVE-2024-29745 – An information disclosure flaw was found in the bootloader component.

CVE-2024-29748 – A privilege escalation flaw in the firmware.

See more: DarkGate malware exploits Microsoft flaw

Google says there is evidence to suggest the vulnerabilities may be subject to limited, targeted exploitation, according to an advisory published on April 2, 2024.

Although the tech giant did not reveal further details about the nature of the attacks exploiting these flaws, GrapheneOS administrators report that they are being actively exploited by criminal companies.

CVE-2024-29745 refers to a vulnerability in the software used to support unlocking, upgrading , and locking functions. This information was shared via a series of posts on X (formerly Twitter).

Forensic science companies are rebooting devices into “After First Unlock” mode in fastboot mode on Pixels and other devices in order to exploit any vulnerabilities and then clear the memory.

GrapheneOS reports that CVE-2024-29748 can be exploited by local attackers to abort a factory reset triggered via the API .

google zero day

Read also: Apple: What security flaws did iOS 17.4.1 fix?

About two months later, the GrapheneOS team said that criminal groups are exploiting vulnerabilities in Google Pixel and Samsung Galaxy phones to steal data and spy when the devices are not in idle mode.

He also suggested that Google add an feature to make it harder to exploit firmware flaws.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS