Google warns of actively exploited Pixel firmware zero-day
ID: 7ef8e7b0-79c0-5a94-8885-d48735b70930
STIX ID: report--7ef8e7b0-79c0-5a94-8885-d48735b70930
Feed Name: Bleeping Computer
Google released June 2024 security updates for Pixel devices addressing 50 vulnerabilities, including CVE-2024-32896 — a high-severity privilege escalation in Pixel firmware that Google warns may be under limited targeted exploitation; the report also recalls previously exploited Pixel zero-days used by forensic firms (CVE-2024-29748/CVE-2024-29745) and mentions an actively exploited Arm Mali GPU use-after-free (CVE-2024-4610). Users are urged to install the Pixel updates (Android 14 QPR3 for Pixels) because some fixes are not backported to older Android releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
