Facebook Twitter Instagram
    • Privacy Policy
    • Contact Us
    Facebook Twitter Instagram Pinterest Vimeo
    AI Home SecurityAI Home Security
    • Home
    • Home Security
    • Cyber Security
    • Biometric Technology
    Contact
    AI Home SecurityAI Home Security
    Cyber Security

    Android Zero-Day Flaws in Pixel Phones Exploited by Forensic Companies

    justmattgBy justmattgApril 3, 2024No Comments2 Mins Read

    [ad_1]

    Apr 03, 2024NewsroomMobile Security / Zero Day

    Android Zero-Day Flaw

    Google has disclosed that two Android security flaws impacting its Pixel smartphones have been exploited in the wild by forensic companies.

    The high-severity zero-day vulnerabilities are as follows –

    • CVE-2024-29745 – An information disclosure flaw in the bootloader component
    • CVE-2024-29748 – A privilege escalation flaw in the firmware component

    “There are indications that the [vulnerabilities] may be under limited, targeted exploitation,” Google said in an advisory published April 2, 2024.

    While the tech giant did not reveal any other information about the nature of the attacks exploiting these shortcomings, the maintainers of GrapheneOS said they “are being actively exploited in the wild by forensic companies.”

    Cybersecurity

    “CVE-2024-29745 refers to a vulnerability in the fastboot firmware used to support unlocking/flashing/locking,” they said in a series of posts on X (formerly Twitter).

    “Forensic companies are rebooting devices in After First Unlock state into fastboot mode on Pixels and other devices to exploit vulnerabilities there and then dump memory.”

    GrapheneOS noted that CVE-2024-29748 could be weaponized by local attackers to interrupt a factory reset triggered via the device admin API.

    The disclosure comes more than two months after the GrapheneOS team revealed that forensic companies are exploiting firmware vulnerabilities that impact Google Pixel and Samsung Galaxy phones to steal data and spy on users when the device is not at rest.

    It also urged Google to introduce an auto-reboot feature to make exploitation of firmware flaws more difficult.

    Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



    [ad_2]

    Source link

    Previous ArticleGoogle Chrome Beta Tests New DBSC Protection Against Cookie-Stealing Attacks
    Next Article U.S. Cyber Safety Board Slams Microsoft Over Breach by China-Based Hackers
    justmattg
    • Website

    Related Posts

    Cyber Security

    Name That Toon: Last Line of Defense

    April 16, 2024
    Cyber Security

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    April 16, 2024
    Cyber Security

    Middle East Cyber Ops Intensify, With Israel the Main Target

    April 16, 2024
    Add A Comment

    Leave A Reply Cancel Reply

    Facebook Twitter Instagram Pinterest
    • Privacy Policy
    • Contact Us
    AI Home Security © 2025 All rights reserved | Designed By ESmartsSolution

    Type above and press Enter to search. Press Esc to cancel.

    ↑