Google Warns: Android Zero-Day Flaws in Pixel Phones Exploited by Forensic Companies
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-29748 +1 in the same advisory: …29745 | Local Privilege Escalation in Google Pixel (Android), Exploited in the Wild Google Pixel devices running affected Android software contain a privilege escalation flaw (CVE-2024-29748) caused by a logic error that allows a security bypass. Exploitation is local to the device and requires user interaction, but the attacker needs no additional execution privileges to complete the escalation. A successful exploit grants the attacker elevated privileges on the device with high impact on confidentiality, integrity, and availability. All unpatched Google Android Pixel devices are affected; the source data does not specify exact affected version ranges. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2024-04-04, and press reporting describes Google patching actively exploited Pixel zero-day flaws, with reporting tying the exploitation to forensic/phone-cracking companies. Do: Update Pixel devices with Google's latest Android security update and verify the Android security patch level is April 2024 or later in Settings > About phone; this is a CISA KEV entry, so apply vendor mitigations promptly or discontinue use per the KEV required action. Because exploitation requires local access and user interaction, restrict device access to untrusted parties and avoid side-loading untrusted apps on unpatched devices. No public proof-of-concept is known, but active exploitation means patching should not wait. | 7.8 group max | <1% | KEV |
| mass≈tens of millions of Pixel smartphones (estimated active install base; only devices not yet on the vendor's security update are exploitable) |
Full article266 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 03, 2024Mobile Security / Zero Day
Google has disclosed that two Android security flaws impacting its Pixel smartphones have been exploited in the wild by forensic companies.
The high-severity zero-day vulnerabilities are as follows -
- CVE-2024-29745 - An information disclosure flaw in the bootloader component
- CVE-2024-29748 - A privilege escalation flaw in the firmware component
"There are indications that the [vulnerabilities] may be under limited, targeted exploitation," Google said in an advisory published April 2, 2024.
While the tech giant did not reveal any other information about the nature of the attacks exploiting these shortcomings, the maintainers of GrapheneOS said they "are being actively exploited in the wild by forensic companies."
"CVE-2024-29745 refers to a vulnerability in the fastboot firmware used to support unlocking/flashing/locking," they said in a series of posts on X (formerly Twitter).
"Forensic companies are rebooting devices in After First Unlock state into fastboot mode on Pixels and other devices to exploit vulnerabilities there and then dump memory."
GrapheneOS noted that CVE-2024-29748 could be weaponized by local attackers to interrupt a factory reset triggered via the device admin API.
The disclosure comes more than two months after the GrapheneOS team revealed that forensic companies are exploiting firmware vulnerabilities that impact Google Pixel and Samsung Galaxy phones to steal data and spy on users when the devices are not at rest.
It also urged Google to introduce an auto-reboot feature to make exploitation of firmware flaws more difficult.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/04/google-warns-android-zero-day-flaws-in.html