Google has released updates for 50 security vulnerabilities affecting Pixel and warned that one of them had been used in attacks as a zero-day (i.e. before releasing the updates).

This zero-day vulnerability is tracked as CVE-2024-32896 and allows elevation of privilege (EoP) in the Pixel firmware. It has been rated as a high severity issue.
“There are indications that CVE-2024-32896 may be under limited, targeted exploitation,” warned this Tuesday.
See also: Black Basta ransomware exploited Windows zero-day vulnerability
“All supported Google devices will receive an update to the 2024-06-05 patch level . We encourage all customers to accept these updates on their devices “.
Google identified 44 other security flaws in this month's Pixel update bulletin. Seven of these are privilege escalation vulnerabilities that are considered critical and affect various subcomponents.
It's worth noting that Pixel devices receive separate security and bug fix updates from the standard monthly patches distributed to all Android OEMs, even though they run Android too.
See also: TellYouThePass ransomware exploits PHP vulnerability
To apply the security, Pixel users need to go to Settings > Security & privacy > System & updates > Security update, tap Install , and restart the device.

To protect themselves from vulnerabilities, users must ensure that their devices are always up to date.
Additionally, users should avoid installing apps from untrusted sources. Apps from the Google Play Store are more likely to have been checked for malware. Using strong and unique passwords for each account can reduce the risk of a breach. Password managers can help create and store these passwords. Enabling two-factor authentication (2FA) adds an extra layer of security to accounts, making it more difficult for unauthorized individuals to access them.
See also: Microsoft Patch Tuesday June 2024: Fixes 51 vulnerabilities
Additionally, users should be cautious of emails and text messages containing links or attachments from unknown sources, as these may contain malware.
Finally, installing and regularly updating a reliable antivirus software can help detect and remove malware that exploits vulnerabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
