Google Warns of Active Exploitation of Pixel Firmware Zero-Day Vulnerability
Marketing · 2024-09-01

Google Warns of Active Exploitation of Pixel Firmware Zero-Day Vulnerability

Google has warned about the active exploitation of a high-severity vulnerability in the firmware of its Pixel smartphones. 

The zero-day flaw tracked as CVE-2024-32896 is an elevation of privilege issue that could allow attackers to gain elevated system privileges on affected devices.

The disclosure comes as part of Google's June 2024 security updates, which addressed 50 vulnerabilities across various components of the Pixel ecosystem. Among these, five vulnerabilities impacted Qualcomm chipsets, while others affected critical components such as the modem, trusty, and ACPM.

While Google has not shared more details about the attacks exploiting the zero-day vulnerability, the company has acknowledged that there are "indications that CVE-2024-32896 may be under limited, targeted exploitation." 

The vulnerability, which resides in the Pixel firmware, could potentially enable an attacker to escalate their privileges on a compromised device, granting them access to sensitive data and system resources. Google has urged Pixel users to promptly apply the June 2024 security updates, which address the zero-day vulnerability along with the other reported issues.

The June 2024 updates are available for a wide range of supported Pixel devices, including the Pixel 5a with 5G, Pixel 6a, Pixel 6, Pixel 6 Pro, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel 8, Pixel 8 Pro, Pixel 8a, and the recently released Pixel Fold. 

Users can install the updates by navigating to Settings > Security & privacy > System & updates > Security update, and then tapping "Install" followed by restarting their device.

This is not the first time Google has grappled with actively exploited vulnerabilities in its Pixel ecosystem. Earlier in April, the tech giant resolved two security flaws in the bootloader and firmware components (CVE-2024-29745 and CVE-2024-29748) that were being weaponized by forensic companies to gain unauthorized access to sensitive data on Pixel devices.

The revelation of an actively exploited zero-day vulnerability in the Pixel firmware comes just days after Arm, the leading chip designer, warned users of a memory-related vulnerability (CVE-2024-4610) in its Bifrost and Valhall GPU kernel drivers that had also come under active exploitation.

熱門文章
超級PAC籌資4800萬美元:體育博彩勢力加碼
合規與政策
新澤西州7月博彩收入創6.06億美元新高,頒布禁令
合規與政策
橫跨全球6個城市,灰度8場派對邀你共看世界盃,重塑高質量社交新場景
灰度頭條
菲律賓博彩技術賽道迎來新變局,B2B 供應模式加速滲透
東南亞資訊
斯里蘭卡博弈產業大轉型,官方:劍指南亞拉斯維加斯
合規與政策
西班牙監管機構警告在線賭博平臺存在身份盜竊行為
合規與政策
菲律賓網絡賭博和加密貨幣仍構成持續的洗錢風險
東南亞資訊
GGC Awards 2026 璀璨科倫坡:致敬 iGaming 行業的領航者與創新力量
灰度頭條
JILI 宣佈與全球板球傳奇 AB de Villiers(ABD)達成重磅戰略合作
體育遊戲
越南博彩管控逐步放寬,惟本土需求仍顯乏力
東南亞資訊
印第安納州在線賭場法案在眾議院委員會停滯不前
合規與政策
英國確認各垂直行業的賭博稅稅率
合規與政策
哈薩克計劃對線上賭場促銷活動進行處罰
合規與政策
印度最高法院受理公益訴訟,要求全國禁封「偽裝」成社交遊戲的賭博平台
合規與政策
巴西擬將博弈稅率提高至24% 稅收將用於社保與醫療領域
合規與政策
首頁
遊戲
合作
發現
我的