Google has warned that a security flaw impacting Pixel Firmware has been exploited in the wild as a zero-day.
https://source.android.com/docs/security/bulletin/pixel/2024-06-01
The high-severity vulnerability, tagged as CVE-2024-32896, has been described as an elevation of privilege issue in Pixel Firmware.
The company did not share any additional details related to the nature of attacks exploiting it, but noted "there are indications that CVE-2024-32896 may be under limited, targeted exploitation."
@ecksmc The GrapheneOS team has a thread providing a bit more information about the vulnerability and the fix:
@john_b thanks for that 👍
ICYMI
Update now! Google Pixel vulnerability is under active exploitation
#CoSoSec #Pixel #Google
https://www.malwarebytes.com/blog/news/2024/06/update-now-google-pixel-vulnerability-is-under-active-exploitation
Updates to address this issue are available for supported Pixel devices, such as Pixel 5a with 5G, Pixel 6a, Pixel 6, Pixel 6 Pro, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel 8, Pixel 8 Pro, Pixel 8a, and Pixel Fold.