Google Discloses Android Zero Day Vulnerability on Pixel, Samsung, Huawei, Xiaomi Phones

The vulnerability has been exploited by a company called the NSO Group based in Israel.

Advertisement
By Tasneem Akolawala | Updated: 4 October 2019 18:26 IST
Highlights
  • The flaw can be used by an attacker to gain root access of a device
  • Pixel 3 series is not vulnerable, Pixel, Pixel 2 to get patch soon
  • The patch available on the Android Common Kernel as well

Google has already told its Android partners about the issue

Google has discovered a security flaw in its Android OS' kernel code that is not only affecting its Pixel phones, but also phones from Samsung, Huawei, Xiaomi, and others. A similar Android OS flaw was fixed in 2017, but it has now cropped up on newer software versions as well. This vulnerability has been given the zero-day status as instances of it being used in the real world have been found. The vulnerability has been exploited by a company called the NSO Group based in Israel. This company is known for creating exploits, including a mobile spyware called Pegasus.

Google has published the proof of concept for the Android OS vulnerability, so users can check if it affects other devices as well. The tech giant confirms that affected devices include Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Huawei P20, Redmi 5A, Redmi Note 5, Mi A1, Oppo A3, Moto Z3, Oreo LG phones, Samsung Galaxy S7, Samsung Galaxy S8, and Samsung Galaxy S9. There's no guarantee that other devices aren't vulnerable, and therefore the proof of concept will help in ascertaining and adding to the list.

Advertisement

The vulnerability can be exploited when the target installs a malicious app, therefore rendering it less dangerous than the others. "This issue is rated as High severity on Android and by itself requires installation of a malicious application for potential exploitation. Any other vectors, such as via web browser, require chaining with an additional exploit,” Project Zero member Tim Willis wrote below the post. However, it can be used by an attacker to gain root access of a device."It is a kernel privilege escalation using a use-after free vulnerability, accessible from inside the Chrome sandbox," the post adds.

Google says that it has already notified its Android partners, and has made the patch available on the Android Common Kernel as well. Pixel and Pixel 2 users will get the patch alongside the October update. Pixel 3 series is not vulnerable to this exploit. Project Zero normally offers a 90-day breather for developers to fix an issue before making it public, but in the event of active exploits, the vulnerability was published in just seven days. The Android Project Zero page adds that an Android exploit attributed to the NSO Group was found, and that the bug was allegedly being used or sold by the NSO Group.

Advertisement

We recommend that you update your Pixel phones as soon as you receive the October patch, and hopefully OEMs should release the patch to affected devices soon.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Turbo 6X Series Will Launch in China on This Date
  2. How to Watch WWDC 2026 Live on YouTube, Apple TV, and More
  3. Capcom Reveals Resident Evil Veronica at Summer Game Fest
  4. Asus Dawn 7 Pro Series Launched With AMD Ryzen AI Chip, Two Display Options
  5. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  6. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  7. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  8. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  9. WhatsApp Users on iOS Are Finally Getting Access to This Useful Feature
  10. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  1. Resident Evil Veronica Revealed at Summer Game Fest; Launch Set for 2027
  2. Microsoft Reportedly Working on Shared Audio Feature on Windows 11 Alongside Tweaked Widgets
  3. WhatsApp Multi-Account Support on iOS Reportedly Rolling Out to More Users
  4. HTX Delists USD1 Stablecoin, Asks World Liberty Financial to Reverse Freeze on Exchange's Addresses
  5. Asus Dawn 7 Pro Series Launched With Up to 16-Inch 144Hz Display, AMD Ryzen AI 7 445 Chip: Price, Features
  6. Redmi Turbo 5 Confirmed to Launch in India With Identical Dual Rear Camera Setup as Chinese Variant
  7. OnePlus Turbo 6X Series Launch Date Announced Along With Key Specifications, Features
  8. WWDC 2026: Tim Cook’s Final Apple Keynote Marks the End of an Era
  9. Infinix Smart 20 Launched in India With MediaTek Helio G81 Ultimate SoC, Slim 7.7mm Profile: Price, Features
  10. Infinix Hot 70 Pro India Launch Timeline Leaked; Could Feature Dimensity 7100 Chip, 6,000mAh Battery
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.