
"Google's Response to Exploited Pixel Vulnerabilities: Patched Zero-Day Flaws and New Pixel Watch Feature"
Google has disclosed that two high-severity zero-day vulnerabilities affecting its Pixel smartphones have been exploited by forensic companies, with indications of limited, targeted exploitation. The vulnerabilities include an information disclosure flaw in the bootloader component and a privilege escalation flaw in the firmware component. These flaws are being actively exploited in the wild by forensic companies, allowing them to reboot devices and exploit vulnerabilities to dump memory. The disclosure comes after previous reports of forensic companies exploiting firmware vulnerabilities in Pixel and Samsung Galaxy phones to steal data and spy on users, prompting calls for Google to introduce an auto-reboot feature to make exploitation more difficult.