Google Discloses Android Zero Day Vulnerability on Pixel, Samsung, Huawei, Xiaomi Phones

The vulnerability has been exploited by a company called the NSO Group based in Israel.

Advertisement
By Tasneem Akolawala | Updated: 4 October 2019 18:26 IST
Highlights
  • The flaw can be used by an attacker to gain root access of a device
  • Pixel 3 series is not vulnerable, Pixel, Pixel 2 to get patch soon
  • The patch available on the Android Common Kernel as well

Google has already told its Android partners about the issue

Google has discovered a security flaw in its Android OS' kernel code that is not only affecting its Pixel phones, but also phones from Samsung, Huawei, Xiaomi, and others. A similar Android OS flaw was fixed in 2017, but it has now cropped up on newer software versions as well. This vulnerability has been given the zero-day status as instances of it being used in the real world have been found. The vulnerability has been exploited by a company called the NSO Group based in Israel. This company is known for creating exploits, including a mobile spyware called Pegasus.

Google has published the proof of concept for the Android OS vulnerability, so users can check if it affects other devices as well. The tech giant confirms that affected devices include Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Huawei P20, Redmi 5A, Redmi Note 5, Mi A1, Oppo A3, Moto Z3, Oreo LG phones, Samsung Galaxy S7, Samsung Galaxy S8, and Samsung Galaxy S9. There's no guarantee that other devices aren't vulnerable, and therefore the proof of concept will help in ascertaining and adding to the list.

Advertisement

The vulnerability can be exploited when the target installs a malicious app, therefore rendering it less dangerous than the others. "This issue is rated as High severity on Android and by itself requires installation of a malicious application for potential exploitation. Any other vectors, such as via web browser, require chaining with an additional exploit,” Project Zero member Tim Willis wrote below the post. However, it can be used by an attacker to gain root access of a device."It is a kernel privilege escalation using a use-after free vulnerability, accessible from inside the Chrome sandbox," the post adds.

Google says that it has already notified its Android partners, and has made the patch available on the Android Common Kernel as well. Pixel and Pixel 2 users will get the patch alongside the October update. Pixel 3 series is not vulnerable to this exploit. Project Zero normally offers a 90-day breather for developers to fix an issue before making it public, but in the event of active exploits, the vulnerability was published in just seven days. The Android Project Zero page adds that an Android exploit attributed to the NSO Group was found, and that the bug was allegedly being used or sold by the NSO Group.

Advertisement

We recommend that you update your Pixel phones as soon as you receive the October patch, and hopefully OEMs should release the patch to affected devices soon.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi A7 Pro 5G Goes on Sale in India: See Price, Features and Offers
  2. DJI Osmo Pocket 4 Design Renders Leaked Ahead of April 16 Launch
  3. Motorola Edge 70 Pro Might Launch in India With This MediaTek Chip
  4. Google App for Windows Rolls Out Globally With These Features
  5. Google Chrome's 'Skills' Feature Lets You Execute AI Tasks With One Click
  6. Oppo Find X9s to Launch Globally Alongside Find X9 Ultra: See Design
  7. Apple Business Now Available in Over 200 Countries: What You Need to Know
  8. Lenovo Will Launch This New Y70 Series Gaming Phone Next Month
  1. Oppo F33 5G Launched in India With Dimensity 6360 Chip, 7,000mAh Battery: Price, Specifications
  2. Oppo F33 Pro 5G Launched in India With 7,000mAh Battery, 50-Megapixel Rear Camera: Price, Specifications
  3. Google App for Windows Rolls Out With AI Mode, System-Wide Search and Lens Features
  4. Redmi A7 Pro 5G With 6,300mAh Battery and 6.9-Inch Display Goes on Sale in India: Price, Offers
  5. Bloodborne Animated Film Adaptation in the Works at Sony
  6. DJI Osmo Pocket 4 Design Renders Leaked Ahead of Launch With 1-Inch Sensor, 4K 240fps Support
  7. OnePlus Ace 6 Ultra Confirmed to Launch Soon; Design, Colourway Teased
  8. Google Chrome Updated With AI-Powered 'Skills' Feature That Lets Users Execute AI Tasks With a Click
  9. Gemini Personal Intelligence Rolls Out in India With App Integration, Contextual AI Responses
  10. Amazon Announces Globalstar Acquisition; Partners With Apple for Satellite Features on iPhone, Apple Watch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.