"Google's Response to Exploited Pixel Vulnerabilities: Patched Zero-Day Flaws and New Pixel Watch Feature"

Google has disclosed that two high-severity zero-day vulnerabilities affecting its Pixel smartphones have been exploited by forensic companies, with indications of limited, targeted exploitation. The vulnerabilities include an information disclosure flaw in the bootloader component and a privilege escalation flaw in the firmware component. These flaws are being actively exploited in the wild by forensic companies, allowing them to reboot devices and exploit vulnerabilities to dump memory. The disclosure comes after previous reports of forensic companies exploiting firmware vulnerabilities in Pixel and Samsung Galaxy phones to steal data and spy on users, prompting calls for Google to introduce an auto-reboot feature to make exploitation more difficult.
- Google Warns: Android Zero-Day Flaws in Pixel Phones Exploited by Forensic Companies The Hacker News
- Your Google Pixel Phone's April Update Arrived Droid Life
- Pixel Watch gets a new way to tell the time with 'Vibration watch' 9to5Google
- Google Patches Exploited Pixel Vulnerabilities SecurityWeek
- Google fixes two Pixel zero-day flaws exploited by forensics firms BleepingComputer
Reading Insights
0
20
1 min
vs 2 min read
59%
257 → 106 words
Want the full story? Read the original article
Read on The Hacker News