• News/
  • https://www.bleepingcomputer.com/news/security/grapheneos-frequent-android-auto-reboots-block-firmware-exploits/

GrapheneOS: Frequent Android auto-reboots block firmware exploits

BleepingComputer
·
Bill Toulas
·
Published Jan 14, 2024
·
Updated

The GrapheneOS team behind the privacy and security-focused Android-based operating system with the same name is suggesting that Android should introduce an auto-reboot feature to make exploitation of firmware flaws more difficult. The project revealed that it recently reported firmware vulnerabilities impacting Android devices such as Google Pixel and Samsung Galaxy phones, which could be exploited to steal data and spy on users when the device is not at rest.

When a device is “at rest,” it means that it is either turned off or has not been unlocked after booting up. In this state, privacy protections are very high and the mobile device is not fully functional because encryption keys are still not available for installed apps to use. The first unlock after a reboot causes multiple cryptographic keys to move to the quick access memory so installed apps to work properly and the device switches to a "not at rest" state. The GrapheneOS team highlights that locking the screen after using the device does not place it back into the "at rest" state because some security exemptions persist. Rebooting the device terminates all temporary states, processes, or activities that could be exploited and requires authentication like PIN, password, or biometric verification to unlock, thereby re-engaging all security mechanisms. Although GrapheneOS devs have not shared many details about the exploited firmware bugs, they proposed a generic mitigation that would work well in most cases: an au...

Read full article

Affected Software

3 affected components
Android OS
Google Pixel
Samsung Galaxy
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What features did GrapheneOS propose to improve Android security?

GrapheneOS proposed an auto-reboot feature to enhance security against firmware exploits.

2

What is the main focus of GrapheneOS?

GrapheneOS is focused on privacy and security for Android users.

3

Which devices are specifically mentioned as affected by these firmware exploits?

The affected devices include Google Pixel and Samsung Galaxy smartphones.

4

How does frequent auto-rebooting enhance firmware exploit security?

Frequent auto-rebooting makes it harder for attackers to exploit firmware vulnerabilities.

5

What organization is behind the GrapheneOS operating system?

The GrapheneOS team is responsible for developing the privacy and security-focused operating system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203