# Google just fixed two critical Android zero-days and 60 other flaws

**URL:** https://discuss.privacyguides.net/t/google-just-fixed-two-critical-android-zero-days-and-60-other-flaws/26510
**Category:** News
**Tags:** article
**Created:** 2025-04-07T20:41:32Z
**Posts:** 5

## Post 1 by @KevPham — 2025-04-07T20:41:32Z

> **[Google just patched two critical Android zero-days exploited by hackers —...](https://www.tomsguide.com/computing/online-security/google-just-fixed-two-critical-android-zero-days-and-60-other-flaws-update-your-phone-right-now)**
>
> Latest Android security update also contains fixes for 60 other vulnerabilities

Google has fixed 62 vulnerabilities, including at least 2 zero-days, in the latest security update. These zero-days were used by Serbian authorities to target student activists with Cellebrite.

> Of these now fixed 62 vulnerabilities, the majority of them are high-severity elevation of privilege flaws while two are zero-day flaws that are much easier for hackers to exploit in their attacks.
> 
> The first zero-day (tracked as [CVE-2024-43197](https://nvd.nist.gov/vuln/detail/CVE-2024-53197)) is a high-severity [privilege escalation flaw](https://www.tomsguide.com/computing/online-security/apple-just-patched-its-first-zero-day-flaw-of-the-year-update-your-iphone-and-mac-right-now) in the Linux kernel’s USB-audio driver for ALSA devices. It was reportedly exploited by authorities in Serbia to unlock confiscated Android devices using a zero-day exploit chain created by an Israeli digital forensics company called Cellebrite.
> 
> The second zero-day (tracked as [CVE-2024-53150](https://nvd.nist.gov/vuln/detail/CVE-2024-53150)) is an [Android Kernel information disclosure vulnerability](https://www.tomsguide.com/phones/android-phones/google-just-fixed-a-zero-day-kernel-flaw-used-by-hackers-and-47-other-vulnerabilities-update-your-android-phone-right-now) that’s caused by an out-of-bound read weakness. If exploited, it can allow local attackers with access to your phone to access sensitive information without any user interaction.

These vulnerabilities were mostly [benign](https://grapheneos.social/@GrapheneOS/114297999497874017) on devices with Graphene OS installed. In fact, they have been [patched](https://bsky.app/profile/grapheneos.org/post/3lmajx53fgs2k) for quite some time now.

Such fixes were only brought to android devices just now; however, most devices will receive updates later than the stock Pixel.

---

## Post 2 by @anon36940904 — 2025-04-07T20:45:08Z

Remember the days when we were all in awe of Stuxnet? Boy.. simpler times.

---

## Post 3 by @anonfox — 2025-04-07T21:00:21Z

> **[GrapheneOS (@GrapheneOS@grapheneos.social)](https://grapheneos.social/@GrapheneOS/114297999497874017)**
>
> CVE-2024-53150: heap overflow (read) in a Linux kernel USB sound card driver
> CVE-2024-53197: heap overflow (write) in a Linux kernel USB sound card driver
> 
> These vulnerabilities were being exploited by Cellebrite for data extraction from locked...

---

## Post 4 by @KevPham — 2025-04-07T21:37:46Z

I edited my post to include Mastodon instead of Bluesky. Thanks for reminding me of that!

---

## Post 5 by @anon73250778 — 2025-04-08T01:22:01Z

> [@KevPham](#):
>
> These vulnerabilities were mostly [benign](https://grapheneos.social/@GrapheneOS/114297999497874017) on devices with Graphene OS installed. In fact, they have been [patched](https://bsky.app/profile/grapheneos.org/post/3lmajx53fgs2k) for quite some time now.

Hey I’m glad devices are up to date…
