Google fixes Android kernel zero-day exploited in targeted attacks

Share:

Android security updates this month patch 46 vulnerabilities, including a high-severity remote code execution (RCE) exploited in targeted attacks.

The zero-day, tracked as CVE-2024-36971, is a use after free (UAF) weakness in the Linux kernel’s network route management. It requires System execution privileges for successful exploitation and allows altering the behavior of certain network connections.

Google says that “there are indications that CVE-2024-36971 may be under limited, targeted exploitation,” with threat actors likely exploiting to gain arbitrary code execution without user interaction on unpatched devices.

Clément Lecigne, a security researcher from Google’s Threat Analysis Group (TAG), was tagged as the one who discovered and reported this zero-day vulnerability.

Even though Google has yet to provide details about how the flaw is being exploited and what threat actor is behind the attacks, Google TAG security researchers frequently identify and disclose zero-days used in state-sponsored surveillance software attacks to target high-profile individuals.

“Source code patches for these issues will be released to the Android Open Source Project (AOSP) repository in the next 48 hours,” explains the advisory.

Earlier this year, Google patched another zero-day exploited in attacks: a high-severity elevation of privilege (EoP) flaw in the Pixel firmware, tracked as CVE-2024-32896 by Google and CVE-2024-29748 by GrapheneOS (which found and reported the flaw).

Forensic companies exploited this vulnerability to unlock Android devices without a PIN and gain access to the stored data.

Google has released two patch sets for the August security updates, the 2024-08-01 and 2024-08-05 security patch levels. The latter includes all the security fixes from the first set and additional patches for third-party closed-source and Kernel components, like a critical vulnerability (CVE-2024-23350) in a Qualcomm closed-source component.

Notably, not all Android devices might need security vulnerabilities that apply to the 2024-08-05 patch level. Device vendors may also prioritize deploying the initial patch level to streamline the update process. However, this does not necessarily indicate an increased risk of potential exploitation.

It’s important to note that while Google Pixel devices receive monthly security updates immediately after release, other manufacturers may require some time before rolling out the patches. The delay is necessary for additional testing of the security patches to ensure compatibility with various hardware configurations.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:02 am, Jun 21, 2025
weather icon 17°C
L: 16° | H: 19°
clear sky
Humidity: 78 %
Pressure: 1020 mb
Wind: 6 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
16° | 19°°C 0.2 mm 20% 10 mph 78 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 26°°C 0.34 mm 34% 15 mph 77 % 1013 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
15° | 23°°C 0 mm 0% 14 mph 75 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
15° | 25°°C 0.2 mm 20% 14 mph 72 % 1016 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
17° | 21°°C 1 mm 100% 10 mph 85 % 1011 mb 0 mm/h
Today 4:00 am
weather icon
17° | 17°°C 0 mm 0% 4 mph 78 % 1020 mb 0 mm/h
Today 7:00 am
weather icon
18° | 20°°C 0 mm 0% 6 mph 69 % 1020 mb 0 mm/h
Today 10:00 am
weather icon
24° | 27°°C 0 mm 0% 8 mph 48 % 1019 mb 0 mm/h
Today 1:00 pm
weather icon
31° | 31°°C 0 mm 0% 9 mph 25 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
32° | 32°°C 0 mm 0% 10 mph 23 % 1016 mb 0 mm/h
Today 7:00 pm
weather icon
26° | 26°°C 0 mm 0% 9 mph 27 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
25° | 25°°C 0.2 mm 20% 5 mph 39 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0.34 mm 34% 7 mph 66 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,797.43
-1.23%
Ethereum(ETH)
€2,107.48
-3.88%
Tether(USDT)
€0.87
0.01%
XRP(XRP)
€1.84
-1.96%
Solana(SOL)
€121.70
-4.60%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.141925
-3.91%
Shiba Inu(SHIB)
€0.000010
-1.59%
Pepe(PEPE)
€0.000009
-1.73%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top