Google Discloses Android Zero Day Vulnerability on Pixel, Samsung, Huawei, Xiaomi Phones

The vulnerability has been exploited by a company called the NSO Group based in Israel.

Advertisement
By Tasneem Akolawala | Updated: 4 October 2019 18:26 IST
Highlights
  • The flaw can be used by an attacker to gain root access of a device
  • Pixel 3 series is not vulnerable, Pixel, Pixel 2 to get patch soon
  • The patch available on the Android Common Kernel as well

Google has already told its Android partners about the issue

Google has discovered a security flaw in its Android OS' kernel code that is not only affecting its Pixel phones, but also phones from Samsung, Huawei, Xiaomi, and others. A similar Android OS flaw was fixed in 2017, but it has now cropped up on newer software versions as well. This vulnerability has been given the zero-day status as instances of it being used in the real world have been found. The vulnerability has been exploited by a company called the NSO Group based in Israel. This company is known for creating exploits, including a mobile spyware called Pegasus.

Google has published the proof of concept for the Android OS vulnerability, so users can check if it affects other devices as well. The tech giant confirms that affected devices include Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Huawei P20, Redmi 5A, Redmi Note 5, Mi A1, Oppo A3, Moto Z3, Oreo LG phones, Samsung Galaxy S7, Samsung Galaxy S8, and Samsung Galaxy S9. There's no guarantee that other devices aren't vulnerable, and therefore the proof of concept will help in ascertaining and adding to the list.

The vulnerability can be exploited when the target installs a malicious app, therefore rendering it less dangerous than the others. "This issue is rated as High severity on Android and by itself requires installation of a malicious application for potential exploitation. Any other vectors, such as via web browser, require chaining with an additional exploit,” Project Zero member Tim Willis wrote below the post. However, it can be used by an attacker to gain root access of a device."It is a kernel privilege escalation using a use-after free vulnerability, accessible from inside the Chrome sandbox," the post adds.

Advertisement

Google says that it has already notified its Android partners, and has made the patch available on the Android Common Kernel as well. Pixel and Pixel 2 users will get the patch alongside the October update. Pixel 3 series is not vulnerable to this exploit. Project Zero normally offers a 90-day breather for developers to fix an issue before making it public, but in the event of active exploits, the vulnerability was published in just seven days. The Android Project Zero page adds that an Android exploit attributed to the NSO Group was found, and that the bug was allegedly being used or sold by the NSO Group.

Advertisement

We recommend that you update your Pixel phones as soon as you receive the October patch, and hopefully OEMs should release the patch to affected devices soon.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Series 5G Confirmed to Launch in India Soon
  2. Oppo Reno 15 Pro Mini Confirmed to Launch in India Alongside These Models
  3. OnePlus Reportedly Developing New Smartphone for India, Global Markets
  4. Here's When the Redmi Pad 2 Pro 5G Will Launch in India
  5. iQOO Z11 Turbo Design Teased; Specifications Leaked
  6. OnePlus 15R Goes on Sale in India For the First Time Today: Price, Offers
  7. Xiaomi Watch 5, Xiaomi Buds 6 to Launch Alongside Xiaomi 17 Ultra
  8. Instagram Could Embrace Long-Form Video Content to Compete With TikTok
  9. OnePlus Turbo Visits Geekbench With This Snapdragon Chipset
  10. Here's When the Samsung Galaxy S26 Series Could Reach Stores in 2026
  1. OnePlus Phone Codenamed ‘Volkswagen’ With Snapdragon 8s Gen 4 Chip Tipped to Launch in India, Global Markets
  2. How to Keep Your Free Perplexity Pro on Airtel: New Card Requirement Explained
  3. Asus VM670KA AiO All-in-One Desktop PC With 27-Inch Display, Ryzen AI 7 350 Chip Launched in India
  4. A Knight of the Seven Kingdoms OTT Release: Know When and Where to Watch This Prequel of Game of Thrones
  5. Nobody 2 Now Streaming Online: Know Everything About This American Action Thriller Film
  6. Osiris Now Streaming on JioHotstar: Everything You Need to Know
  7. Revolver Rita OTT Release Date Revealed: Know Everything About Streaming, Plot, Cast, and More
  8. ChatGPT Agreeing With Users is Dangerous, Says Lawyer in Murder-Suicide Case: Report
  9. CES 2026: Samsung to Expand Bespoke Appliances With Improved AI Vision, Google Gemini AI
  10. Redmi Pad 2 Pro 5G India Launch Date Announced; Teaser Confirms 12,000mAh Battery
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.