0day in Pixel: Google releases an emergency patch for its smartphones

Tomcat

Professional
Messages
2,380
Reputation
4
Reaction score
407
Points
83
Update quickly before hackers pave a cyberpath to your gadget.

Following Microsoft's now-familiar Patch Tuesday, Google also released updates to address 50 security vulnerabilities in its Pixel devices and warned that one of them, tracked as CVE-2024-32896, is an escalation of privilege (EoP) bug and has already been exploited in real attacks as a Zero-day vulnerability.

“There are indications that CVE-2024-32896 may have been used previously in limited targeted attacks,” the company warned. “All supported Google devices will receive an update to patch level 2024-06-05. We encourage all Pixel users to install these updates on their devices immediately."

Google also flagged 44 other security bugs specifically affecting Pixel devices. Seven of them are privilege escalation vulnerabilities and are considered critical.

Pixel devices, although running Android, receive separate security updates and bug fixes that differ from the standard monthly patches distributed to all Android device manufacturers. This is due to their exclusive features and capabilities, as well as the unique hardware platform controlled personally by Google.

For more information about the June Pixel updates, see Google's smartphone security bulletin . And to apply the update, Pixel users need to go to Settings > Security & Privacy > System & Updates > Security Update, tap Install, and restart the device to complete the update process.

In April, Google also addressed two other 0day vulnerabilities in the Pixel that were used by forensics firms to unlock phones without a PIN and access data. CVE-2024-29745 has been flagged as a high-severity Pixel bootloader information disclosure vulnerability, and CVE-2024-29748 has been flagged as a privilege escalation vulnerability in Pixel firmware.
 
Top