Google details 0-click bug in Pixel 6 modem: Advises users to disable 2G

LAS VEGAS — Google’s Android Red Team outlined a now-patched critical 0-click vulnerability in its Pixel 6 modem stack that allows a skilled adversary to hijack a target’s Android handset simply by initiating a call to the victim. During the Wednesday Black Hat session, four of Google’s Android Red Team members demonstrated how two Pixel modem vulnerabilities (CVE-2022-20170, CVE-2022-20405) could be chained together to first downgrade a targeted Pixel’s cellular modem communication to the second-generation (2G) wireless standard and hijack the handset, all with the help of a low-cost $1,000 home-brew cellphone base station.

Source: SC Magazine

 


Date:

Categorie(s):

Tag(s):