Google Warns of Active Exploitation of Pixel Firmware Zero-Day Vulnerability
Marketing · 2024-09-01

Google Warns of Active Exploitation of Pixel Firmware Zero-Day Vulnerability

Google has warned about the active exploitation of a high-severity vulnerability in the firmware of its Pixel smartphones. 

The zero-day flaw tracked as CVE-2024-32896 is an elevation of privilege issue that could allow attackers to gain elevated system privileges on affected devices.

The disclosure comes as part of Google's June 2024 security updates, which addressed 50 vulnerabilities across various components of the Pixel ecosystem. Among these, five vulnerabilities impacted Qualcomm chipsets, while others affected critical components such as the modem, trusty, and ACPM.

While Google has not shared more details about the attacks exploiting the zero-day vulnerability, the company has acknowledged that there are "indications that CVE-2024-32896 may be under limited, targeted exploitation." 

The vulnerability, which resides in the Pixel firmware, could potentially enable an attacker to escalate their privileges on a compromised device, granting them access to sensitive data and system resources. Google has urged Pixel users to promptly apply the June 2024 security updates, which address the zero-day vulnerability along with the other reported issues.

The June 2024 updates are available for a wide range of supported Pixel devices, including the Pixel 5a with 5G, Pixel 6a, Pixel 6, Pixel 6 Pro, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel 8, Pixel 8 Pro, Pixel 8a, and the recently released Pixel Fold. 

Users can install the updates by navigating to Settings > Security & privacy > System & updates > Security update, and then tapping "Install" followed by restarting their device.

This is not the first time Google has grappled with actively exploited vulnerabilities in its Pixel ecosystem. Earlier in April, the tech giant resolved two security flaws in the bootloader and firmware components (CVE-2024-29745 and CVE-2024-29748) that were being weaponized by forensic companies to gain unauthorized access to sensitive data on Pixel devices.

The revelation of an actively exploited zero-day vulnerability in the Pixel firmware comes just days after Arm, the leading chip designer, warned users of a memory-related vulnerability (CVE-2024-4610) in its Bifrost and Valhall GPU kernel drivers that had also come under active exploitation.

热门文章
灰度世界杯嘉年华狂欢派对吉隆坡站即将开启,业务拓展人脉社交从马来西亚开始
灰度头条
英国确认各垂直行业的赌博税税率
游戏风向
超级PAC筹资4800万美元:体育博彩势力加码
游戏风向
巴西拟将博彩税率提高至24% 税收将用于社保和医疗领域
游戏风向
2027 Global Game Connect(GGC)斯里兰卡招商全面开启!业务人脉尽在掌握!
灰度头条
新泽西州7月博彩收入创6.06亿美元新高,颁布禁令
游戏风向
密西西比州众议院委员会推进提议增加赌场税的法案
游戏风向
BETFAIR 网络攻击80万用户资料泄露
游戏风向
越南在线博彩业政策收紧 催生市场新机遇
东南亚资讯
GGC Awards 2026 璀璨科伦坡:致敬 iGaming 行业的领航者与创新力量
灰度头条
巴西颁布新法赋权央行封锁非法博彩账户及 Pix 交易
支付动态
印度最高法院受理公益诉讼,要求全国禁封“伪装”成社交游戏的赌博平台
游戏风向
PropellerAds 分享了新的 iGaming 案例研究:在 3 个月实现 97,674 次安装和 12,701 笔存款
广告营销
JILI 宣布与全球板球传奇 AB de Villiers(ABD)达成重磅战略合作
体育游戏
灰度在iGB L!VE 2026展位T70和你相约7月,一起点燃伦敦的热情!
灰度头条
首页
游戏
合作
发现
我的