Your Android phone might be hacked without you knowing. Update now to fix these critical security issues



Google has released an emergency Android security update after discovering two actively exploited zero-day vulnerabilities that could allow hackers to access user data without any interaction from the victim. The April 2025 patch, which started rolling out on Monday, is aimed at fixing 62 different vulnerabilities—two of which are considered especially dangerous.

The most serious issue, tracked as CVE-2024-53197, is a privilege escalation flaw in the USB-audio driver of the Linux kernel used by Android. According to Google’s security bulletin, it could “lead to remote escalation of privilege with no additional execution privileges needed” and “user interaction is not needed for exploitation.”

The second flaw, CVE-2024-53150, is tied to an “out-of-bound read” in Android’s kernel, which could allow local attackers to access sensitive data without the user’s knowledge. Both vulnerabilities were discovered by Google’s Threat Analysis Group and Amnesty International, and were reportedly exploited by Cellebrite—an Israeli digital forensics firm that supplies data extraction tools to law enforcement.

Used in Real-World Attacks

Amnesty International said it found these vulnerabilities being used to hack into the phone of a Serbian student activist. According to the findings, Cellebrite used the flaws as part of a zero-day exploit chain to break into the locked Android device.

The non-profit’s spokesperson, Hajira Maryam, stated they had no additional comments to share at the moment. Google also declined to provide further detail on how the second vulnerability might have been used.

Google has confirmed that the vulnerabilities are being “under limited, targeted exploitation,” a warning that emphasizes the urgency of the situation. GrapheneOS, a security-focused Android variant, noted that these were “both vulnerabilities for locked devices” and claimed their system “made both far harder to exploit while unlocked.”

Update Rollout and Device Impact

Pixel users are receiving the update first. Google said its partners were notified about these issues at least a month before publication and that source code patches would be released within 48 hours of the advisory.However, due to Android’s fragmented ecosystem, users of other brands like Samsung, OnePlus, or Motorola may have to wait for their respective manufacturers to release the patch. While Samsung was previously criticized for delays in patch rollouts, it has included both CVE-2024-53150 and CVE-2024-53197 in its April update.

Global Warnings and Broader Cybersecurity Concerns

This emergency update coincides with a global alert from several intelligence agencies. The U.K.’s National Cyber Security Centre (NCSC), along with cybersecurity agencies from the U.S., Canada, Germany, Australia, and New Zealand, issued warnings about the use of two spyware tools, MOONSHINE and BADBAZAAR, by threat actors linked to the Chinese state. These tools reportedly “trojanise” legitimate apps to gain access to microphones, cameras, messages, photos, and even location data.

Such tools have been used to target specific communities and civil society organizations, underlining the need for rapid security response.

Security experts advise all Android users to update their devices immediately. If you are using a Pixel phone, the update is already available. Users of other devices should keep checking for updates and install them as soon as they are released.

Additionally, users are encouraged to use reputable antivirus software, avoid clicking on suspicious links, and refrain from opening attachments from unknown sources. While 62 vulnerabilities may seem alarming, it is crucial to note that these issues have now been patched. The biggest risk now lies in users failing to apply the update.



Source link

Share

Latest Updates

Frequently Asked Questions

Related Articles

Telesat pitches Lightspeed as stopgap to Europe’s IRIS²

TAMPA, Fla. — Canada’s Telesat is pitching Lightspeed as a bridge to IRIS²...

Apple watchOS 26 system requirements: will it run on your Apple Watch?

The latest Apple smartwatch software is called watchOS 26. After months of beta...

Fixing Hallucinations Would Destroy ChatGPT, Expert Finds

In a paper published earlier this month, OpenAI researchers said they'd found the...

Centre’s AI roadmap targets $1.7 trillion GDP boost by 2035

New Delhi: The government aims to generate additional $1.7 trillion in economic value...
sabung ayam online sabung ayam online sabung ayam online sabung ayam online sabung ayam online Sabung Ayam Online Sv388 Sv388 SV388 sabung ayam online sabung ayam online Sabung Ayam Online sabung ayam online sabung ayam online sabung ayam online Sabung ayam online Sabung ayam online SV388 sabung ayam online sabung ayam online sabung ayam online sabung ayam online sabung ayam online sabung ayam online SV388 sabung ayam online SV388 SV388 Sabung Ayam Online Sabung Ayam Online Sabung Ayam Online Sabung Ayam Online Sv388 SV388 SV388 sabung ayam online sv388 sv388 sabung ayam online sv388
judi bola judi bola Judi bola SBOBET judi bola judi bola judi bola Judi Bola Online judi bola judi bola judi bola judi bola judi bola judi bola juara303 juara303 Judi bola online judi bola judi bola judi bola judi bola judi bola judi bola judi bola judi bola SBOBET judi bola judi bola judi bola Judi Bola SBOBET88 SBOBET88 judi bola judi bola judi bola JUDI BOLA ONLINE JUDI BOLA ONLINE SBOBET88 Judi Bola Judi Bola judi bola judi bola judi bola judi bola judi bola Judi Bola Online judi bola judi bola judi bola judi bola mix parlay
CASINO ONLINE SLOT GACOR live casino mahjong ways Live Casino Online Slot Gacor Mahjong Ways slot pulsa Casino Online Slot Gacor Mix Parlay live casino online live casino online LIVE CASINO ONLINE LIVE CASINO ONLINE slot pulsa slot pulsa slot pulsa Mpo Slot
https://ejurnal.staidarulkamal.ac.id/ https://doctorsnutritionprogram.com/ https://nielsen-restaurante.com/ https://www.atobapizzaria.com.br/ https://casadeapoio.com.br/ https://bracoalemao.com.br/ https://letspetsresort.com.br/ https://mmsolucoesweb.com.br/ https://procao.com.br/
Rahasia Kemenangan di Mahjong Wild Pemain Tidak Menyangka Pola Scatter Jangan Anggap Remeh Mahjong Wild Pemain Pemula Heran Setelah Coba Mahjong Wild Menemukan Pola Rahasia yang Bikin Scatter Muncul Pola Scatter Rahasia yang Baru Terbongkar Pola Rahasia Pemain Pemula Terbongkar Mereka Ketagihan Karena Sering Dapat Kemenangan Mereka Ketagihan Karena Sering Dapat Kemenangan Trik Sederhana Saat Taruhan Kecil Pola Wild Liar Tersembunyi Bisa Menggandakan uang Pola Rahasia Baru Bisa Menghasilkan Wild Buktikan Pola Wild Liar dan Scatter Hitam Kaya Setelah Main Mahjong Wild Pria Asal Nepal Obrak-Abarik Kantor DPR