Google's Project Zero finds 18 zero-day vulnerabilities, including four top-severity flaws, affecting some Samsung phones and other devices with Exynos chipsets
Google's security research unit is sounding the alarm on a set of vulnerabilities it found in certain Samsung chips included …
TechCrunch Zack Whittaker
Context & Ripple Effects
Google’s disclosure follows an earlier Project Zero report on five Mali GPU flaws for which Samsung, Xiaomi, Google and other device makers had not yet released patches. That history makes a new chipset-level finding consequential because remediation depends on more than the researcher or chip designer.
Project Zero had also identified vendor changes to the Android kernel as a source of added attack surface, framing the Exynos findings within a broader problem of securing customized device software.
First-order effects
- Samsung and other makers of affected Exynos devices must assess and distribute fixes for 18 reported zero-days, including four top-severity issues.
- Owners of the affected Samsung phones and other Exynos-based devices face exposure until their device maker delivers the relevant remediation.
Second-order effects
- Google’s Android security ecosystem faces renewed pressure to move fixes through chip, operating-system and handset-vendor layers faster than in the earlier Mali GPU case.
- Samsung’s Exynos platform becomes a more immediate security consideration for device buyers and partners as the findings extend beyond a single handset model.
Third-order effects
- The pattern reinforces that Android security outcomes are shaped by the slowest participant in a layered supply chain—chipset provider, platform owner and device vendor—rather than by vulnerability discovery alone.
- If repeated disclosures continue to outpace vendor updates, differentiated patch delivery and software customization will become a more durable competitive liability for Android device makers.
The trend: Mobile security is increasingly being tested at the intersection of chipset flaws and fragmented vendor-controlled update pipelines.
Related: Google · Samsung · Exynos · Project Zero’s Exynos modem vulnerability report · Project Zero’s Mali GPU flaw report · Android kernel customization and security
Related Coverage
- Multiple Internet to Baseband Remote Code Execution Vulnerabilities in Exynos Modems Project Zero · Tim Willis
- Google: Turn off VoLTE, Wi-Fi calling due to severe Exynos modem vulnerabilities on Pixel 6, more 9to5Google · Abner Li
- Product Security Update Samsung Semiconductor Global
- Google Finds Dozens of Android Devices Can Be ‘Silently’ Compromised PCMag · Matthew Humphries
- Google Reveals Samsung Phones Could Be Hacked Without Owners Knowing: Here's How International Business Times · Dane Enerio
- Baseband RCE flaws in Samsung's Exynos chipsets expose devices to remote hack Security Affairs · Pierluigi Paganini
- New Samsung 0-Click Security Threat Alert, Disable Wi-Fi Calling Now Forbes · Davey Winder
- 18 zero-day flaws impact Samsung Android handsets, wearables and telematics SC Media · Tom Spring
- Project Zero: Samsung Mobile Chipsets Vulnerable to Baseband Code Execution Exploits SecurityWeek · Ryan Naraine
- Insecure Exynos modems put dozens of Samsung devices, and other Android phones, at risk Android Police · Jay Bonggolto
- Google finds 18 zero-day vulnerabilities in Samsung Exynos chipsets BleepingComputer · Sergiu Gatlan
- Your Samsung phone may have a big security flaw - here's how to stay safe TechRadar · Hamish Hector
- Google says hackers could silently own your phone until Samsung fixes its modems The Verge · Mitchell Clark
- Samsung, Pixel, and Vivo Users are Advised to Turn Off VoLTE and Wi-Fi Calling to Avoid Getting Hacked, Says Google Research Team Wccftech · Furqan Shahid
- A major new Android bug lets hackers take over your devices KnowTechie · Kevin Raposo
- Turn off 2 Pixel and Samsung Galaxy settings to prevent hackers from owning your phone BGR · Chris Smith
- Google advises Android users to take action after finding 18 zero-day vulnerabilities in popular phones TechSpot · Rob Thubron
- Nasty bug allows hackers to take over many Android phones. Here's what you can do. Mashable
- Samsung Galaxy and Google Pixel phones can be easily hacked! Gizchina · Abdullah
- Samsung Exynos modems were found to have a vulnerability, here's what company replied SamNews 24 · Ragini
- Google Project Zero team finds critical security flaw in Samsung modems TechCircle
- Google Uncovers 18 Severe Security Vulnerabilities in Samsung Exynos Chips The Hacker News
- Google: turn off Wi-Fi Calling and VoLTE in Pixel/Samsung devices affected by major security issues gHacks Technology News · Martin Brinkmann
- Samsung hasn't patched a critical bug affecting many Galaxy phones with Exynos chips SamMobile · Sagar Naresh
- Google's Project Zero Discovers 18 Zero-Day Vulnerabilities in Exynos Chipsets TechPowerUp · Fouquin
- [Samsung Responded] Severe Exynos modem vulnerabilities found, these models are affected Sammy Fans · James Lee Taylor
- PSA: Disable Wi-Fi Calling, VoLTE on Pixel & Samsung Phones IMMEDIATELY WebProNews · Matt Milano
- Microsoft Targets Critical Outlook Zero-Day Flaw eSecurityPlanet · Jeff Goldman
- Google Warns Samsung and Pixel Phone Owners About 18 Dire Exploits CNET · David Lumb
- Google warns users against 18 bugs in mass-level Android phones Techlusive · Priya Singh
- Samsung “internet-to-baseband” bug can be attacked over the phone iTnews · Richard Chirgwin
Discussion
-
@zackwhittaker@mastodon.social
Zack Whittaker
on mastodon
New, by me: Google's Project Zero is sounding the alarm over four zero-day flaws in Samsung chips, affecting dozens of Android models. — Google says the flaws can be “silently and remotely” exploited over the cell network. …
-
@itswillis
Tim Willis
on x
What happens when you get @natashenka, @ifsecure, @_fel1x, @i41nbeer and @tehjh working collaboratively on a new attack surface for the team? This: https://googleprojectzero.blogspot.com/ ... The blogpost also includes actions that users can take to protect themselves while waiti…
-
@jsrailton
John Scott-Railton
on x
2/ Baseband vulnerabilities = freaky. Baseband = the “other OS” on your phone handling calling & cellular network etc. Think of it as below the waterline of Android / iOS & what users can see. They are hard to find & defend against. Great to see Project Zero helping to fix.
-
@gadgetsdata
Debayan Roy
on x
Google project Zero security team has found 18 active vulnerabilities because of 🔴Exynos Modem on these 12 phones: Galaxy M33, A53, A33, A21, A13, A12, M12, M13, A04 series Pixel 6A ,6,6 Pro Hackers can access your📱using your phone no. A security patch can fix these issues! https…
-
@wtogami
Warren Togami
on x
Writing other commentary here instead of distracting from the important post. * It seems curious that Google seems totally uncoordinated on this. Their corporate comms are dead silent on why the patch isn't out except for a customer service agent apology screenshot. The Project..…
-
@maxwinebach
Max Weinbach
on x
RIP Exynos modems Pixel 6 and 7 patched with Match update fwiw. Samsung hasn't patched anything on their devices yet. https://twitter.com/...
-
@securityweek
@securityweek
on x
Critical flaws expose Samsung's Exynos modems to “Internet-to-baseband remote code execution” attacks with no user interaction. Project Zero says an attacker only needs the victim's phone number. @ryanaraine reports: - https://www.securityweek.com/ ...
-
@jorgeorchilles
Jorge Orchilles
on x
Well this isn't good... 18 0day vulnerabilities in Exynos Modems produced by Samsung Semiconductor (that means a lot of Samsung phones)... 4 allow Internet-to-baseband RCE... “we believe that skilled attackers would be able to quickly create an https://googleprojectzero.blogspot.…
-
@lorenzofb
@lorenzofb
on x
NEW: Google's Project Zero has found a lot of high severity vulnerabilities in certain Samsung chips included in dozens of Android models. Samsung has had more than 90 days to patch, but hasn't done it yet, according to Google's @maddiestone. https://techcrunch.com/...
-
@ryanaraine
Ryan Naraine
on x
Pretty significant Project Zero findings 🩹 18 zero-days in Samsung Exynos chipsets, some nasty enough to cause “Internet-to-baseband remote code execution” with no user interaction. Attacker only needs victim's phone number 👩 Quick story: https://www.securityweek.com/ ...
-
@ryanaraine
Ryan Naraine
on x
p0 barebones advisory: “Due to a very rare combination of level of access these vulns provide and the speed with which we believe a reliable operational exploit could be crafted, we've made a policy exception to delay disclosure [on 4 nastiest bugs]” https://googleprojectzero.blo…
-
@lukolejnik
Lukasz Olejnik
on x
Only a phone number needed to exploit a vulnerability in Samsung Exynos chipset (baseband modem) vulnerability, affects Samsung devices, and Google Pixel. Disable wifi calls and Voice-over-LTE. https://googleprojectzero.blogspot.com/ ...
-
@xiatian
Xia
on x
Exploitable baseband-level RCE in Google Pixel 6/7 series and a whole lot of Samsung phones, disable VoLTE and Wi-Fi Calling until patched: https://9to5google.com/...
-
@alesandroortizr
@alesandroortizr
on x
🚨Breaking my Twitter silence for this: 🚨Internet-exploitable RCE affecting Samsung devices + other devices with Exynos chipsets. Mitigations available. Check if your device is affected and apply mitigations: https://googleprojectzero.blogspot.com/ ... https://techcrunch.com/... …
-
@artemr
Artem Russakovskii
on x
Google Project Zero discovered vulnerabilities affecting Android phones with Samsung's Exynos chips that result in remote and silent full pwnage with nothing but a phone number. https://googleprojectzero.blogspot.com/ ... Here are the affected phones. Pixels have been patched alr…
-
@phhusson
Husson Pierre-Hugues
on x
Security flaws in VoLTE. Who would have guessed? A year ago I started a FLOSS unprivileged userspace VoLTE implementation. If you want to join that effort ping me. Currently in Kotlin, but could be rewritten in rust which would help GNU environments. https://googleprojectzero.blo…
-
@jsrailton
John Scott-Railton
on x
WHOA: own a recent Samsung or Vivo phone? @Google's Project Zero found serious baseband vulnerabilities. While awaiting fixes, disable Wi-Fi calling & VoLTE. + do your updates! 1/ By @natashenka @ifsecure @_fel1x @i41nbeer & @tehjh https://googleprojectzero.blogspot.com/ ... http…