Security vulnerabilities on Pixel devices worry the US government

Security vulnerabilities on Pixel devices show signs of being intentionally exploited.

In the latest monthly update for Pixel, Google noted that the vulnerability in question, identified as CVE-2024-32896, "shows signs of being intentionally exploited," according to Phone Arena.

A zero-day vulnerability (a vulnerability in software or hardware that is typically not identified by the vendor and for which no patch or other fix is ​​available) was listed in the Pixel update bulletin as "high-risk". high severity".

According to Forbes, this vulnerability has made the US government so worried that it ordered all federal employees who own Pixel devices to update their phones by July 4 "or stop using the device". .

While the warning is aimed at US government agencies, private companies and even individuals using public Wi-Fi to connect to the Internet should install the latest security updates as soon as possible. Good.

The US government's warning comes from a catalog of known exploitable vulnerabilities (KEV) managed by the US Cybersecurity and Infrastructure Security Agency (CISA). "Android Pixel contains an unknown vulnerability in the firmware that causes an escalation of privilege (EoP) error," the advisory said. Privilege escalation would allow an attacker to use an application to capture information of users of Pixel devices.

While the US government appears to be solely focused on Pixel users, GrapheneOS says that the vulnerability is not just a concern for users of this device, saying: "Security flaws have been fixed on the device Pixels in the June update and will be fixed on other Android devices when the device is updated to Android 15."

To apply the security update, Pixel users need to go to Settings > Security & privacy > System & updates > Security updates, tap Install and restart the device to complete. update process. 

