• News/
  • https://www.bleepingcomputer.com/news/security/google-fixes-two-pixel-zero-day-flaws-exploited-by-forensics-firms/

Google fixes two Pixel zero-day flaws exploited by forensics firms

BleepingComputer
·
Bill Toulas
·
Published Apr 3, 2024
·
Updated

Google has fixed two Google Pixel zero-days exploited by forensic firms to unlock phones without a PIN and gain access to the data stored within them. Although Pixels run Android, they receive separate updates from the standard monthly patches distributed to all Android device OEMs. This is due to their unique hardware platform, over which Google has direct control, and the exclusive features and capabilities. While the April 2024 security bulletin for Android didn't contain anything severe, the corresponding April 2024 bulletin for Pixel devices disclosed active exploitation of two vulnerabilities tracked as CVE-2024-29745 and CVE-2024-29748 flaws. "There are indications that the following may be under limited, targeted exploitation," warned Google. CVE-2024-29745 is marked as a high-severity information disclosure flaw in the Pixel's bootloader, while CVE-2024-29748 is described as a high-severity elevation of privilege bug in the Pixel firmware. Security researchers for GrapheneOS, a privacy-enhanced and security-focused Android distribution, disclosed on X that they discovered forensic companies actively exploited the flaws. The flaws allow companies to unlock and access memory on Google Pixel devices, which they have physical access to.

GrapheneOS discovered and reported these flaws a few months back, sharing some information publicly but keeping the specifics undisclosed to avoid fueling widespread exploitation when a patch wasn't available yet. "CVE-2024-29745 refers...

Read full article

Affected Software

2 affected components
Google Pixel
Google Android
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the fixing of two zero-day vulnerabilities in Google Pixel devices exploited by forensics firms.

2

What security implications are discussed in the article?

The vulnerabilities allowed unauthorized access to phone data by bypassing security measures like PIN codes.

3

What products are affected by the vulnerabilities mentioned in the article?

The affected products include Google Pixel phones and the Android operating system.

4

Who exploited the vulnerabilities in Google Pixel devices?

Forensics firms were identified as the entities exploiting these vulnerabilities to unlock and access data on Pixel phones.

5

How has Google responded to these zero-day vulnerabilities?

Google has released fixes to address the two zero-day flaws in the affected Pixel devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203