Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Review: Apple iPhone 17 Pro and iPhone 17 Pro Max

17 September 2025

Nvidia CEO Jensen Huang Is Bananas for Google Gemini’s AI Image Generator

17 September 2025

Review: Samsung HW-Q990F Dolby Atmos Soundbar System

17 September 2025
Facebook X (Twitter) Instagram
Just In
  • Review: Apple iPhone 17 Pro and iPhone 17 Pro Max
  • Nvidia CEO Jensen Huang Is Bananas for Google Gemini’s AI Image Generator
  • Review: Samsung HW-Q990F Dolby Atmos Soundbar System
  • Review: Apple iPhone Air
  • This Giant Subterranean Neutrino Detector Is Taking On the Mysteries of Physics
  • Meta Is Debuting New Smart Glasses Today. Here’s How to Watch
  • Save $100 or More on a Mac Mini Today
  • Hollow Knight: Silksong Review – Punishing Grandeur
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » Google quietly fixed USB flaw that left over a billion Android devices exposed
News

Google quietly fixed USB flaw that left over a billion Android devices exposed

News RoomBy News Room1 March 20253 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

In the first week of February, Google published its usual Android Security Bulletin, detailing security flaws that have been plugged to strengthen the platform safety. These flaws are usually declared once they have been fixed, except in special circumstances.

February is one of those rare situations for a kernel-level, high-severity flaw that was still being actively exploited at the time of the bulletin’s release. “There are indications that CVE-2024-53104 may be under limited, targeted exploitation,” says the release note.

The flaw was first reported by experts at Amnesty International, which describes it as an “out-of-bound write in the USB Video Class (UVC) driver.” The researchers add that since it’s a kernel-level exploit, it impacts overs over a billion Android devices, irrespective of the brand label.


Please enable Javascript to view this content

Since it’s a zero-day exploit, only the attackers know of its existence, unless security experts sense its presence, develop a fix with the platform’s team, and then widely release it for all affected devices. Two other vulnerabilities, CVE-2024-53197 and CVE-2024-50302, have been fixed at the kernel-level, but haven’t been completely patched at an OS-level by Google

The impact pool is vast

The pool of affected devices is the Android ecosystem, while the attack vector is a USB interface. Specifically, we are talking about zero-day exploits in the Linux kernel USB drivers, which allows a bad actor to bypass the Lock Screen protection and gain deep-level privileged access to a phone via a USB connection.

In this case, a tool offered by Cellebrite was reportedly used to unlock the phone of a Serbian student activist and gain access to data stored on it. Specifically, a Cellebrite UFED kit was deployed by law enforcement officials on the student activist’s phone, without informing them about it or taking their explicit consent.

Amnesty says the usage of a tool like Cellebrite — which has been abused to target journalists and activists widely — was not legally sanctioned. The phone in question was a Samsung Galaxy A32, while the Cellebrite device was able to break past its Lock Screen protection and gain root access.

“Android vendors must urgently strengthen defensive security features to mitigate threats from untrusted USB connections to locked devices,” says Amnesty’s report. This won’t be the first time that the name Cellebrite has appeared in the news.

Update your Android smartphone. ASAP!

The company sells its forensic analysis tools to law enforcement and federal agencies in the US, and multiple other countries, letting them brute-force their way into devices and extract critical information.

In 2019, Cellebrite claimed that it could unlock any Android or Apple device using its Universal Forensic Extraction Device. However, it has also raised ethical concerns and privacy alarms about unfair usage by authorities for surveillance, harassment, and targeting of whistleblowers, journalists, and activists.

A few months ago, Apple also quietly tightened the security protocols with iOS 18.1 update, with the intention of blocking unauthorized access to locked smartphones and preventing exfiltration of sensitive information.











Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleVivo V50 Lite 4G Reportedly Spotted on Google Play Console Showcasing Design, Key Features
Next Article Apple Said to Face French Antitrust Fine for Privacy Control Tool

Related Articles

News

Review: Apple iPhone 17 Pro and iPhone 17 Pro Max

17 September 2025
News

Nvidia CEO Jensen Huang Is Bananas for Google Gemini’s AI Image Generator

17 September 2025
News

Review: Samsung HW-Q990F Dolby Atmos Soundbar System

17 September 2025
News

Review: Apple iPhone Air

17 September 2025
News

This Giant Subterranean Neutrino Detector Is Taking On the Mysteries of Physics

17 September 2025
News

Meta Is Debuting New Smart Glasses Today. Here’s How to Watch

17 September 2025
Demo
Top Articles

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024105 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

5 laptops to buy instead of the M4 MacBook Pro

17 November 202492 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
News

Meta Is Debuting New Smart Glasses Today. Here’s How to Watch

News Room17 September 2025
News

Save $100 or More on a Mac Mini Today

News Room17 September 2025
Gaming

Hollow Knight: Silksong Review – Punishing Grandeur

News Room17 September 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025129 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024105 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks

Review: Apple iPhone Air

17 September 2025

This Giant Subterranean Neutrino Detector Is Taking On the Mysteries of Physics

17 September 2025

Meta Is Debuting New Smart Glasses Today. Here’s How to Watch

17 September 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.