Warning: Google Raises Alarm on Active Exploitation of Pixel Firmware Zero-Day Vulnerability

Tech & AI | June 13, 2024, 4:23 a.m.

Google has recently released patches for 50 security vulnerabilities affecting its Pixel devices, with one already being exploited in targeted attacks as a zero-day. The most significant flaw, CVE-2024-32896, is an elevation of privilege (EoP) vulnerability in the Pixel firmware rated as high severity. The company has warned that this flaw may be under limited targeted exploitation. Additionally, 44 other security bugs were identified in this month's Pixel update bulletin, with seven critical privilege escalation vulnerabilities impacting various subcomponents. Pixel devices receive separate security updates from standard Android patches due to their exclusive features and unique hardware platform controlled by Google. Users are advised to accept the latest updates to their devices to ensure the security and integrity of their Pixel smartphones. Arm also recently warned of a memory-related vulnerability in GPU kernel drivers exploited in the wild. Previously, Google fixed two other Pixel zero-days exploited by forensic firms for unauthorized access.