ARTICLE AD BOX
More bad news for Android users.
CFOTO/Future Publishing via Getty ImagesWe unrecorded successful absorbing times. For nan 3rd period running, Google has confirmed nan bad news that Android phones are nether attack, arsenic different regular monthly information merchandise turns into an emergency update now warning. There is 1 captious quality this clip though, pinch awesome implications for some Pixel and Samsung.
ForbesSamsung’s One UI 7 Decision—Change New Setting Before You UpgradeBy Zak Doffman
“There are indications,” Google warns, that CVE-2024-53150 and CVE-2024-53197 “may beryllium nether limited, targeted exploitation.” The first is simply a representation vulnerability wrong Android’s kernel, leaving a instrumentality exposed to section information exfiltration. If that brings forensic exploits to mind, past nan 2nd vulnerability hammers it home. This is different of nan flaws known to person been exploited by Cellebrite successful Europe.
While Android zero-days whitethorn now beryllium nan norm, what isn’t nan norm is Samsung matching Pixel’s gait successful rushing retired these updates. Last month, the Galaxy-maker missed 1 of Android’s exploited fixes yet again. But CVE-2024-50302 from March is included successful Samsung’s April update, a period down Pixel. Much much notably, some of Android’s April fixes are besides included successful Samsung’s April release. That’s a large deal.
According to Android hardener GrapheneOS, these “2 much vulnerabilities marked arsenic being exploited successful nan chaotic [are]
some vulnerabilities for locked devices,” which its package “made some acold harder to utilization while unlocked.” It says some vulnerabilities “were being exploited by Cellebrite for information extraction from locked Android devices.”
This is captious because Samsung was falling behind successful information updates conscionable arsenic nan Android world obsesses astir its delays connected Android OS upgrades arsenic well. With notable timing, these information updates turned up nan aforesaid time Samsung yet started to rotation retired its unchangeable One UI 7 / Android 15 upgrade to its 2024 and 2023 flagships.
ForbesFBI Warning—Stop These Calls On Your iPhone And Android PhoneBy Zak Doffman
Yet again this period we person seen forensic exploits patched by 1 of Android aliases iPhone, pinch some world operating systems intelligibly susceptible to nan heavy pockets of an manufacture primed to break instrumentality security. Samsung’s One UI 7 incudes caller protections against these forensic exploits and Android 16 looks for illustration it will lucifer iPhone’s non-activity reboot, making specified exploits harder. Interesting times indeed.