Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Android zero-day vulnerability in Pixel phones exploited by forensic firm
    Cyber Security

    Android zero-day vulnerability in Pixel phones exploited by forensic firm

    techempireBy techempire2 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportApril 3, 2024Editorial DepartmentMobile Security/Zero Day

    Android zero-day vulnerabilities

    Google has revealed that two Android security flaws affecting its Pixel smartphones have been widely exploited by forensic firms.

    High-severity zero-day vulnerabilities are as follows:

    • CVE-2024-29745 – There is an information leakage flaw in the bootloader component
    • CVE-2024-29748 – Privilege escalation flaw in firmware components

    “There are signs that [vulnerabilities] May be subject to limited, targeted exploitation,” Google said in an announcement on April 2, 2024.

    While the tech giant did not reveal any other information about the nature of the attacks exploiting the flaws, GrapheneOS maintainers said the flaws “are being actively exploited by forensics companies.”

    Internet security

    “CVE-2024-29745 refers to a vulnerability in the fastboot firmware used to support unlocking/refreshing/locking,” they explain In a series of posts on X (formerly Twitter).

    “Forensics firms are exploiting vulnerabilities on Pixel and other devices by rebooting them into fastboot mode in a post-first-unlock state and then dumping memory.”

    GrapheneOS noted that local attackers may weaponize CVE-2024-29748 to interrupt a factory reset triggered through the device management API.

    The disclosure comes more than two months after the GrapheneOS team disclose Forensics firms are exploiting a firmware vulnerability affecting Google Pixel and Samsung Galaxy phones to steal data and spy on users when the devices are not stationary.

    It also urged Google to introduce an automatic restart feature to make exploiting firmware flaws more difficult.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.