Skip to main content

Google quietly fixed USB flaw that left over a billion Android devices exposed

Official Android mascot and splash screen on a phone.
Denny Müller / Unsplash

In the first week of February, Google published its usual Android Security Bulletin, detailing security flaws that have been plugged to strengthen the platform safety. These flaws are usually declared once they have been fixed, except in special circumstances.

February is one of those rare situations for a kernel-level, high-severity flaw that was still being actively exploited at the time of the bulletin’s release. “There are indications that CVE-2024-53104 may be under limited, targeted exploitation,” says the release note.

Recommended Videos

The flaw was first reported by experts at Amnesty International, which describes it as an “out-of-bound write in the USB Video Class (UVC) driver.” The researchers add that since it’s a kernel-level exploit, it impacts overs over a billion Android devices, irrespective of the brand label.

Since it’s a zero-day exploit, only the attackers know of its existence, unless security experts sense its presence, develop a fix with the platform’s team, and then widely release it for all affected devices. Two other vulnerabilities, CVE-2024-53197 and CVE-2024-50302, have been fixed at the kernel-level, but haven’t been completely patched at an OS-level by Google

The impact pool is vast

The pool of affected devices is the Android ecosystem, while the attack vector is a USB interface. Specifically, we are talking about zero-day exploits in the Linux kernel USB drivers, which allows a bad actor to bypass the Lock Screen protection and gain deep-level privileged access to a phone via a USB connection.

Cellebrite UFED device.
A Cellebrite device used that is used to extract data from smartphones. Cellebrite

In this case, a tool offered by Cellebrite was reportedly used to unlock the phone of a Serbian student activist and gain access to data stored on it. Specifically, a Cellebrite UFED kit was deployed by law enforcement officials on the student activist’s phone, without informing them about it or taking their explicit consent.

Amnesty says the usage of a tool like Cellebrite — which has been abused to target journalists and activists widely — was not legally sanctioned. The phone in question was a Samsung Galaxy A32, while the Cellebrite device was able to break past its Lock Screen protection and gain root access.

“Android vendors must urgently strengthen defensive security features to mitigate threats from untrusted USB connections to locked devices,” says Amnesty’s report. This won’t be the first time that the name Cellebrite has appeared in the news.

Update your Android smartphone. ASAP!

The company sells its forensic analysis tools to law enforcement and federal agencies in the US, and multiple other countries, letting them brute-force their way into devices and extract critical information.

In 2019, Cellebrite claimed that it could unlock any Android or Apple device using its Universal Forensic Extraction Device. However, it has also raised ethical concerns and privacy alarms about unfair usage by authorities for surveillance, harassment, and targeting of whistleblowers, journalists, and activists.

A few months ago, Apple also quietly tightened the security protocols with iOS 18.1 update, with the intention of blocking unauthorized access to locked smartphones and preventing exfiltration of sensitive information.

Nadeem Sarwar
Nadeem is a tech and science journalist who started reading about cool smartphone tech out of curiosity and soon started…
Google Messages might finally fix this frequent annoyance
The Google Messages app on the Galaxy S25 Ultra.

Though most text messages you typically send might be just a few words long, occasionally you need to draft out a longer message -- and that can be annoying on an Android device. Google Messages has an infamously small compose box, which has been a source of annoyance for many users. Now, though, that looks set to change, with a new feature spotted in the latest beta version of the Messages app of an expandable compose box.

The change was spotted in an APK teardown of the latest Android beta by Android Authority, which suggests that a change to the way the Google Messages app functions is in the works. Getting at the new compose box took some "tinkering," according to the site, but they were able to unlock a version of the compose box which can be expanded to 12 lines of text rather than the currently available four lines.

Read more
Google fixes the vibrating Android 16 bug that was frustrating users
Android-16-Beta 3.2

Android 16 arrived last month, and users have been enjoying new features including live updates from apps like food delivery or ride hailing, audio sharing so you can listen to music with friends over Bluetooth, and support for adjusting screen refresh rates to keep up with newer displays. However, there have been a few annoyances with the new features too, like issues with the haptic feedback. Now, Google is rolling out a new beta version of the OS, Android 16 Beta 3.2, to address these issues.

The fix for haptic feedback is the biggest change in the new release. In Android 16, Google added more options for developers to control the way your phone buzzes when taking certain actions or getting certain notifications. The light vibrations help with navigation and awareness, though these aren't changes to the Android notification system itself -- rather, there are now more options for app developers to make use of fine-grained haptics.

Read more
Google Maps’ new feature sees Android play catchup to iOS
Samsung Galaxy S24 in Marble Gray showing Google Maps.

Android users are getting their first glimpse of a new operating system feature while using Google Maps, as the app is the first to make use of the Live Updates ability that was added for Android 16. The feature will give users updated information in their status bar so they can keep track of ongoing activity such as following directions using maps.

Similar to Apple's Live Activities system, the Android function can potentially be used by a range of apps but has first been seen in Google Maps. "Live Updates are a new class of notifications that help users monitor and quickly access important ongoing activities," Android developers explained in a post highlighting the feature when it was first announced.

Read more