Your Pixel, Galaxy phone may be at risk due to Exynos modem vulnerabilities

What you need to know

  • Google’s Project Zero team has revealed a new vulnerability in the Exynos SoC.
  • Phones with these chipsets include the Pixel 6 series, Pixel 7 series, Galaxy S22 models, and more.
  • The team points to a baseband remote code execution vulnerability that can be executed based on learning the victim’s phone number.

Smartphones are often ranked by chipset performance, but these SoCs can be vulnerable, and new evidence from Google’s Project Zero team suggests that.

Over the past few months, the Project Zero team has discovered 18 zero-day vulnerabilities in devices including Samsung Exynos modems (via 9to5Google).Of these 18, 4 are seriously ill (1 CVE-2023-24033 IDothers have not yet been assigned a CVE-ID), which could allow an attacker to perform remote code execution from the Internet into the baseband.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *