Your Android phone might be hacked without you knowing. Update now to fix these critical security issues



Google has released an emergency Android security update after discovering two actively exploited zero-day vulnerabilities that could allow hackers to access user data without any interaction from the victim. The April 2025 patch, which started rolling out on Monday, is aimed at fixing 62 different vulnerabilities—two of which are considered especially dangerous.

The most serious issue, tracked as CVE-2024-53197, is a privilege escalation flaw in the USB-audio driver of the Linux kernel used by Android. According to Google’s security bulletin, it could “lead to remote escalation of privilege with no additional execution privileges needed” and “user interaction is not needed for exploitation.”

The second flaw, CVE-2024-53150, is tied to an “out-of-bound read” in Android’s kernel, which could allow local attackers to access sensitive data without the user’s knowledge. Both vulnerabilities were discovered by Google’s Threat Analysis Group and Amnesty International, and were reportedly exploited by Cellebrite—an Israeli digital forensics firm that supplies data extraction tools to law enforcement.

Used in Real-World Attacks

Amnesty International said it found these vulnerabilities being used to hack into the phone of a Serbian student activist. According to the findings, Cellebrite used the flaws as part of a zero-day exploit chain to break into the locked Android device.

The non-profit’s spokesperson, Hajira Maryam, stated they had no additional comments to share at the moment. Google also declined to provide further detail on how the second vulnerability might have been used.

Google has confirmed that the vulnerabilities are being “under limited, targeted exploitation,” a warning that emphasizes the urgency of the situation. GrapheneOS, a security-focused Android variant, noted that these were “both vulnerabilities for locked devices” and claimed their system “made both far harder to exploit while unlocked.”

Update Rollout and Device Impact

Pixel users are receiving the update first. Google said its partners were notified about these issues at least a month before publication and that source code patches would be released within 48 hours of the advisory.However, due to Android’s fragmented ecosystem, users of other brands like Samsung, OnePlus, or Motorola may have to wait for their respective manufacturers to release the patch. While Samsung was previously criticized for delays in patch rollouts, it has included both CVE-2024-53150 and CVE-2024-53197 in its April update.

Global Warnings and Broader Cybersecurity Concerns

This emergency update coincides with a global alert from several intelligence agencies. The U.K.’s National Cyber Security Centre (NCSC), along with cybersecurity agencies from the U.S., Canada, Germany, Australia, and New Zealand, issued warnings about the use of two spyware tools, MOONSHINE and BADBAZAAR, by threat actors linked to the Chinese state. These tools reportedly “trojanise” legitimate apps to gain access to microphones, cameras, messages, photos, and even location data.

Such tools have been used to target specific communities and civil society organizations, underlining the need for rapid security response.

Security experts advise all Android users to update their devices immediately. If you are using a Pixel phone, the update is already available. Users of other devices should keep checking for updates and install them as soon as they are released.

Additionally, users are encouraged to use reputable antivirus software, avoid clicking on suspicious links, and refrain from opening attachments from unknown sources. While 62 vulnerabilities may seem alarming, it is crucial to note that these issues have now been patched. The biggest risk now lies in users failing to apply the update.



Source link

Share

Latest Updates

Frequently Asked Questions

Related Articles

Electoral roll revamp: the case for digital transformation

After two decades of silence on one of India’s most critical democratic processes,...

Samara Aerospace pointing technology to be tested in orbit

SAN FRANCISCO – Samara Aerospace’s patented satellite-pointing technology will soon be tested in...

These smart beds began roasting their owners during AWS outage

Owners of Eight Sleep smart beds got anything but a good night’s sleep...

HBO Max price increase now in effect – here’s how much more you’ll have to pay

The streaming service price increases show no sign of slowing. Today, new pricing...
custom cakes home inspections business brokerage life counseling rehab center residences chiropractic clinic surf school merchant advisors poker room med spa facility services creative academy tea shop life coach restaurant life insurance fitness program electrician NDIS provider medical academy sabung ayam online judi bola judi bola judi bola judi bola Slot Mahjong slot mahjong Slot Mahjong judi bola sabung ayam online mahjong ways mahjong ways mahjong ways judi bola SV388 SABUNG AYAM ONLINE GA28 judi bola online sabung ayam online live casino online live casino online SV388 SV388 SV388 SV388 SV388 Mix parlay sabung ayam online SV388 SBOBET88 judi bola judi bola judi bola Reset Pola Blackjack Jadi Kasus Study Mahjong Ways Mahjong Ways Mahjong Ways Mahjong Ways sabung ayam online sabung ayam online judi bola sabung ayam online judi bola Judi Bola Sabung Ayam Online Live Casino Online Sabung Ayam Online Sabung Ayam Online Sabung Ayam Online Sabung Ayam Online Sabung Ayam Online Sabung Ayam Online sabung ayam online judi bola mahjong ways sabung ayam online judi bola mahjong ways mahjong ways sabung ayam online sv388 Sv388 judi bola judi bola judi bola JUARA303 Mahjong ways Judi Bola Judi Bola Sabung Ayam Online Live casino mahjong ways 2 sabung ayam online sabung ayam online mahjong ways mahjong ways mahjong ways SV388 SBOBET88 judi bola judi bola judi bola judi bola judi bola https://himakom.fisip.ulm.ac.id/ SABUNG AYAM ONLINE MIX PARLAY SLOT GACOR JUDI BOLA SV388 LIVE CASINO LIVE CASINO ONLINE Judi Bola Online SABUNG AYAM ONLINE JUDI BOLA ONLINE LIVE CASINO ONLINE JUDI BOLA ONLINE LIVE CASINO ONLINE LIVE CASINO ONLINE sabung ayam online Portal SV388 SBOBET88 SABUNG AYAM ONLINE JUDI BOLA ONLINE CASINO ONLINE MAHJONG WAYS 2 sabung ayam online judi bola SABUNG AYAM ONLINE JUDI BOLA ONLINE Sabung Ayam Online JUDI BOLA Sabung Ayam Online JUDI BOLA SV388, WS168 & GA28 SBOBET88 SV388, WS168 & GA28 SBOBET88 SBOBET88 CASINO ONLINE SLOT GACOR Sabung Ayam Online judi bola