Google has issued a critical warning to Pixel smartphone users who have not installed the latest April 2024 security patch. Two high-severity vulnerabilities, tracked as CVE-2024-29745 and CVE-2024-29748, could potentially be exploited by forensic companies for targeted attacks on Google Pixel devices still on March and older security updates.

While Google doesn’t delve deeper into the details of these vulnerabilities beyond the warning, the folks over at MalwareBytes Labs describe them as follows:

  • CVE-2024-29745: An information disclosure vulnerability in the bootloader component, which is basically a flaw in the bootloader component that could allow unauthorized access to sensitive information stored on your device.
  • CVE-2024-29748: An elevation of privilege (EoP) vulnerability in the Pixel firmware, which describes a vulnerability within the Pixel firmware that opens the door for attackers to gain elevated privileges, potentially gaining deeper control of your device.

Forensic companies and other entities specializing in data extraction often seek out such vulnerabilities to develop advanced tools for accessing locked or encrypted devices. While these tools can be used for legitimate purposes in law enforcement investigations, they also pose a significant risk to the privacy of everyday Pixel users who haven’t updated their software.

Google-Pixel-high-risk-vulnerabilities

Google strongly recommends that all Pixel users install the April 2024 security update immediately since this patch effectively addresses the identified vulnerabilities, minimizing the risk of exploitation.

Staying up-to-date with the latest security patches is crucial to safeguarding your device and personal data. While some users may be hesitant to update due to concerns about potential software issues, the risks associated with unpatched vulnerabilities far outweigh any potential downsides.

Hillary Keverenge
2119 Posts

Tech has been my playground for over a decade. While the Android journey began early, it truly took flight with the revolutionary Lollipop update. Since then, it's been a parade of Android devices (with a sprinkle of iOS), culminating in a mostly happy marriage with Google's smart home ecosystem. Expect insightful articles and explorations of the ever-evolving world of Android and Google products coupled with occasional rants on the Nest smart home ecosystem.

Next article View Article

Google Pixel Watch price drops in France: Check out the best offers available

Google Pixel Watch has received a welcome price reduction across several major retailers in France. This presents a prime opportunity to snag this feature-packed smartwatch at a significant discount...
Apr 04, 2024 1 Min Read