Google fixes two Pixel zero-day flaws exploited by forensics firms. GrapheneOS discovered and reported these flaws.

ForgottenFlux@lemmy.world to Technology@lemmy.world – 438 points –
Google fixes two Pixel zero-day flaws exploited by forensics firms
bleepingcomputer.com

More Information: GrapheneOS Mastodon account

18

Exciting: https://grapheneos.social/@GrapheneOS/112204441311327128

In the near future, we'll be shipping a properly secure implementation of a duress PIN/password along with a properly secure panic wipe based on wiping without requiring a reboot. We also plan to make device admin API use our wipe-without-reboot approach until Android ships one.

love that i switched to graphene. I was hesitant because ages ago i bricked a phone with a random ROM, but boy have things changed.

installing was seriously easy, like in a pinch my elderly parents could probably do it. the result worries better than stock Android imo

Really strongly recommend checking it out if you have a supported devices.

I didn't brick mine, but got very close to it. Was able to run some command prompts to it while it was giving me a blank screen and managed to factory reset/ get it to where I wanted. Man was I worried I just turned my $1,000.00 phone into a paperweight. After that near miss, I gave up on rooting/ custom roms even though I enjoyed tinkering with them. Maybe I should give it another go.

If you just want to play around you can get a Pixel 7a for $374 USD from store.google.com while it's on sale. You can pay in installments.

I don't really like Google as a company, or idea of changing phones often, but it's pretty cheap for a brand new smartphone, and buying from Google gives the option for having an unlocked bootloader unlike if you bought from a service provider's store.

Only thing I hate is the messaging app sucks. I have "enter" key so I cannot make new lines in my messages.

The April 2024 security update for Pixel phones fixes 24 vulnerabilities, including CVE-2024-29740, a critical severity elevation of privilege flaw.

Too bad it doesn't expose which updates were made and which CVEs were patched. I guess it came in the "April 5" security update my phone has now...

It constantly annoys me that it doesn't present a change log for system updates. It's just like here you go, install this, maybe this one has security updates, you'll never know. Doesn't even tell you what version it is installing.

That's why I like Samsung. They at least tell you what kind of update you're installing.

Wish Graphene suports more than just Google Pixel

Some Samsung devices (Galaxy S series) have a proper hardware that met the requirements of GrapheneOS team but Samsung doesn't offer a proper support for other ROM's. Pixel devices are very similar to the old ADP (Android Dev Phone) in matter of software because they are the few one or even the only OEM that provides a smartphone with the ability to lock the bootloader after the installation of a different ROM

Maybe they should just ship grapheneos.

Nah, that would tick off a lot of people because there are compromises to GrapheneOS. I'm fine with those compromises, but others may not be.

Really? I've and literally zero problems or conpromises.

Android Auto has been added very recently, IIRC. So that was missing for a long while

Would be great if they also countered Google's dark patterns in the notification bar toggles and revert back to the old working design. I'm not saying it's even close to the same priority as this. But you know... Google's decisions are downgrading the platform and the experience.