
Google advises disabling Wi-Fi calling and VoLTE to prevent Android hijack bugs.
Google's Project Zero found and reported 18 zero-day vulnerabilities in some Samsung chipsets that could allow an attacker to completely hijack and remote-control Android devices knowing just the phone number. Four of the 18 zero-day flaws can allow internet-to-baseband remote code execution. Skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely. Google issued a fix for one of the severe bugs affecting Pixel devices in its March security update. Until the other manufacturers plug the holes, users are advised to turn off Wi-Fi calling and Voice-over-LTE (VoLTE) to protect against baseband remote code execution if they are using a vulnerable device powered by Samsung's silicon.