Google advises disabling Wi-Fi calling and VoLTE to prevent Android hijack bugs.

Google's Project Zero found and reported 18 zero-day vulnerabilities in some Samsung chipsets that could allow an attacker to completely hijack and remote-control Android devices knowing just the phone number. Four of the 18 zero-day flaws can allow internet-to-baseband remote code execution. Skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely. Google issued a fix for one of the severe bugs affecting Pixel devices in its March security update. Until the other manufacturers plug the holes, users are advised to turn off Wi-Fi calling and Voice-over-LTE (VoLTE) to protect against baseband remote code execution if they are using a vulnerable device powered by Samsung's silicon.
- Google: Turn off Wi-Fi calling, VoLTE to protect your Android from Samsung hijack bugs The Register
- Google: Turn off VoLTE, Wi-Fi calling due to severe Exynos modem vulnerabilities on Pixel 6, more 9to5Google
- Google tells users of some Android phones: Nuke voice calling to avoid infection Ars Technica
- Exynos Vulnerabilities Found, Pixel Phones in Trouble Droid Life
- Google warns users to take action to protect against remotely exploitable flaws in popular Android phones TechCrunch
Reading Insights
0
10
2 min
vs 3 min read
80%
570 → 114 words
Want the full story? Read the original article
Read on The Register