ZeroHour

Search: “bootloader”

7 items in the last 3d

Forgery of C2PA on a Pixel 10

Researcher forged a Google Pixel 10 C2PA content credential with genuine signatures, showing root-level attackers can fake photo provenance.

A Hacker Factor blog post demonstrates an AI-generated 'unicorn glitter milk' news photo carrying a valid, cryptographically signed C2PA manifest traceable to Google's Pixel camera certificate chain, passing validation in Adobe Inspect and the CAI Verify tool with a verified timestamp. The author, working with UMBC's PASAWG working group, reported to Google and C2PA in November 2025 that root access on a Pixel device could sign arbitrary images as camera captures; after 90 days without resolution, details were published. The finding undermines C2PA Assurance Level 2 claims made for Pixel 10 Content Credentials.

Lobsters · security · 14h agoResearch

Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

Google patched Pixel modem zero-day CVE-2026-58704 (CVSS 8.0), exploited in limited targeted attacks, enabling adjacent privilege escalation without user interaction.

Google's September 2026 Pixel security update fixes CVE-2026-58704, a CVSS 8.0 permission bypass caused by a logic error in the cellular modem, allowing remote (proximal/adjacent) elevation of privilege with no user interaction or additional privileges. Google confirms indications of limited, targeted exploitation in the wild but provides no attribution, target count, or attack objectives. The modem location is significant because it operates below much of the Android application security model. The bulletin also patches multiple critical RCE flaws in IMS, libpixelimsmedia, VPU, modem, telephone and BigOcean components, with the 2026-09-05 patch level protecting devices.

Security Affairsupdated · 10h agofirst · 14h agoExploit / PoC in the wild 8 sourcesCVE-2026-58704

Pixel Modem Zero-Day Exploited in Targeted Attacks

Google patched Pixel modem zero-day CVE-2026-58704, a zero-click permission bypass enabling remote privilege escalation, exploited in targeted attacks.

CVE-2026-58704 is a high-severity logic error in the Pixel cellular modem allowing remote (proximal/adjacent) escalation of privilege with no user interaction or additional execution privileges. Google reports limited, targeted exploitation but has not attributed it; the zero-click modem nature suggests commercial spyware or state-sponsored actors. The September Pixel update also fixes more than 100 other Pixel-specific vulnerabilities, nearly 50 of them critical, enabling RCE or privilege escalation.

SecurityWeekupdated · 10h agofirst · 14h agoExploit / PoC in the wild 8 sourcesCVE-2026-58704

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google's September Pixel update patches CVE-2026-58704, a high-severity cellular modem privilege escalation flaw showing signs of limited targeted exploitation.

Google disclosed CVE-2026-58704 (CVSS 8.0), a privilege escalation flaw in the Pixel Cellular Modem caused by a logic error permitting proximal/adjacent privilege escalation with no user interaction or extra privileges needed. Google acknowledged indications the flaw may be under limited, targeted exploitation but did not identify the threat actor. The September 2026 Pixel update fixes 109 additional flaws, including 46 critical-severity issues in components such as BigOcean, Bootloader, IMS, and Trusted Execution Environment, plus two high-severity kernel privilege escalation bugs (CVE-2026-56914, CVE-2026-58773). Security patch level 2026-09-05 or later resolves all identified flaws.

The Hacker Newsupdated · 10h agofirst · 16h agoExploit / PoC in the wild 8 sourcesCVE-2026-58704CVE-2026-56914CVE-2026-58773+1 CVEs

Android 0-day Vulnerability on Google Pixel Devices Actively Exploited in Attacks

Google patched CVE-2026-58704, an actively exploited Android zero-day allowing proximal privilege escalation via the Pixel cellular modem, urging the 2026-09-05 patch.

Google confirmed CVE-2026-58704, a high-severity elevation-of-privilege flaw in the Pixel cellular modem, is being exploited in limited, targeted attacks and shipped emergency fixes in the September 2026 Pixel Update Bulletin. The low-complexity bug requires no user interaction and enables proximal/adjacent privilege escalation with no additional execution privileges, phrasing Google has historically used for spyware-vendor and state-aligned zero-days. The Pixel bulletin patches 110 flaws including 12 critical RCEs, while the broader September Android update addressed roughly 180 vulnerabilities, including Wi-Fi memory-corruption bug CVE-2026-28662.

Cyber Security Newsupdated · 10h agofirst · 18h agoExploit / PoC in the wild 8 sourcesCVE-2026-58704CVE-2026-28662

CareCam CM2507

CISA advisory: seven flaws in CareCam CM2507 IP cameras enable unauthenticated live video access, privileged ONVIF control, credential recovery, and code execution.

CISA advisory ICSA-26-258-08 discloses seven vulnerabilities in CareCam HMT.CM2507 IP cameras running firmware v251211.1507. Issues include missing authentication for network video streaming (CVE-2026-88259, CVSS 3.1 7.5), an empty password on a privileged ONVIF account (CVE-2026-84398), weak legacy hashing of the root password (CVE-2026-85497, CVSS 4.0 9.3 critical), and cleartext storage of Wi-Fi credentials (CVE-2026-81321). Physical-access flaws allow arbitrary code execution from scripts on removable media (CVE-2026-81305) and unauthenticated bootloader access (CVE-2026-85478). The cameras are deployed worldwide in commercial facilities.

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages

Debian 13.7 'trixie' point release bundles 92 security advisories and 106 package updates, including kernel, glibc, u-boot and qemu fixes.

Debian shipped version 13.7 of 'trixie', folding in 92 previously published security advisories and corrections to 106 source packages, including six Linux kernel advisories (DSA-6381, DSA-6393, DSA-6405, DSA-6415, DSA-6466, DSA-6477). glibc fixes a buffer overflow (CVE-2026-5928) and buffer underflow (CVE-2026-5450), with 17 packages rebuilt against the updated library; qemu carries 25 CVEs including a secure boot bypass (CVE-2026-16288), imagemagick 24, wolfssl 15 and perl 13. Boot-chain fixes include a u-boot FIT image verification bypass (CVE-2026-46728), a BOOTP/DHCP buffer overread (CVE-2024-42040), and corrected intermediate certificate verification in sbsigntool. The installer was rebuilt with kernel ABI 6.12.107+deb13, and existing systems receive the fixes through normal package mirror updates.