Google Discloses Android Zero Day Vulnerability on Pixel, Samsung, Huawei, Xiaomi Phones

The vulnerability has been exploited by a company called the NSO Group based in Israel.

Advertisement
By Tasneem Akolawala | Updated: 4 October 2019 18:26 IST
Highlights
  • The flaw can be used by an attacker to gain root access of a device
  • Pixel 3 series is not vulnerable, Pixel, Pixel 2 to get patch soon
  • The patch available on the Android Common Kernel as well

Google has already told its Android partners about the issue

Google has discovered a security flaw in its Android OS' kernel code that is not only affecting its Pixel phones, but also phones from Samsung, Huawei, Xiaomi, and others. A similar Android OS flaw was fixed in 2017, but it has now cropped up on newer software versions as well. This vulnerability has been given the zero-day status as instances of it being used in the real world have been found. The vulnerability has been exploited by a company called the NSO Group based in Israel. This company is known for creating exploits, including a mobile spyware called Pegasus.

Google has published the proof of concept for the Android OS vulnerability, so users can check if it affects other devices as well. The tech giant confirms that affected devices include Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Huawei P20, Redmi 5A, Redmi Note 5, Mi A1, Oppo A3, Moto Z3, Oreo LG phones, Samsung Galaxy S7, Samsung Galaxy S8, and Samsung Galaxy S9. There's no guarantee that other devices aren't vulnerable, and therefore the proof of concept will help in ascertaining and adding to the list.

The vulnerability can be exploited when the target installs a malicious app, therefore rendering it less dangerous than the others. "This issue is rated as High severity on Android and by itself requires installation of a malicious application for potential exploitation. Any other vectors, such as via web browser, require chaining with an additional exploit,” Project Zero member Tim Willis wrote below the post. However, it can be used by an attacker to gain root access of a device."It is a kernel privilege escalation using a use-after free vulnerability, accessible from inside the Chrome sandbox," the post adds.

Advertisement

Google says that it has already notified its Android partners, and has made the patch available on the Android Common Kernel as well. Pixel and Pixel 2 users will get the patch alongside the October update. Pixel 3 series is not vulnerable to this exploit. Project Zero normally offers a 90-day breather for developers to fix an issue before making it public, but in the event of active exploits, the vulnerability was published in just seven days. The Android Project Zero page adds that an Android exploit attributed to the NSO Group was found, and that the bug was allegedly being used or sold by the NSO Group.

Advertisement

We recommend that you update your Pixel phones as soon as you receive the October patch, and hopefully OEMs should release the patch to affected devices soon.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Tipster Leaks Details of the Oppo Find X9 Ultra, Vivo X300 Ultra Cameras
  2. Xiaomi Teases a New Computing Device, New Tablet Expected to Launch Soon
  3. OTT Releases of the Week (Feb 16 - Feb 22): Know What to Watch This Weekend
  4. Motorola Edge 70 Fusion India Launch Teased; Might Launch With This Chip
  5. Redmi A7 Bags Thailand's NBTC Certification, Could Launch Soon
  6. Here's When Xiaomi Will Launch the Xiaomi 17 and Xiaomi 17 Ultra Globally
  1. Astronomers Find ‘Impossible’ Galaxy ACDG-2 With Virtually No Stars and a Massive Dark Matter Core
  2. Google Pixel Call Recording Reportedly Available in Additional Regions Ahead of Global Expansion
  3. Oppo Find X9 Ultra, Vivo X300 Ultra Leak: Tipster Shares Details of Anticipated 200-Megapixel Cameras
  4. Redmi A7 Could Launch Soon as Handset Bags Thailand’s NBTC Certification
  5. Poco X8 Pro, Poco X8 Pro Max Design and Colour Options Seen in Leaked Renders
  6. Hello Bachhon OTT Release Date: When and Where to Watch Vineet Kumar Singh Starrer Online?
  7. Xiaomi Teases India Launch of New Computing Device; New Tablet With Keyboard or Laptop Expected
  8. Realme C83 5G India Price, RAM and Storage Configurations Leaked Online
  9. Xiaomi 17 Series Global Launch Date Announced; Xiaomi 17, Xiaomi 17 Ultra Expected to Debut
  10. Google Blocked 266 Million Risky App Installs, Prevented 1.75 Million Policy-Violating Apps in 2025
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.