Skip to main content
  1. Home
  2. Phones
  3. Mobile
  4. News

Google quietly fixed USB flaw that left over a billion Android devices exposed

Add as a preferred source on Google
Official Android mascot and splash screen on a phone.
Denny Müller / Unsplash

In the first week of February, Google published its usual Android Security Bulletin, detailing security flaws that have been plugged to strengthen the platform safety. These flaws are usually declared once they have been fixed, except in special circumstances.

February is one of those rare situations for a kernel-level, high-severity flaw that was still being actively exploited at the time of the bulletin’s release. “There are indications that CVE-2024-53104 may be under limited, targeted exploitation,” says the release note.

Recommended Videos

The flaw was first reported by experts at Amnesty International, which describes it as an “out-of-bound write in the USB Video Class (UVC) driver.” The researchers add that since it’s a kernel-level exploit, it impacts overs over a billion Android devices, irrespective of the brand label.

Since it’s a zero-day exploit, only the attackers know of its existence, unless security experts sense its presence, develop a fix with the platform’s team, and then widely release it for all affected devices. Two other vulnerabilities, CVE-2024-53197 and CVE-2024-50302, have been fixed at the kernel-level, but haven’t been completely patched at an OS-level by Google

The impact pool is vast

The pool of affected devices is the Android ecosystem, while the attack vector is a USB interface. Specifically, we are talking about zero-day exploits in the Linux kernel USB drivers, which allows a bad actor to bypass the Lock Screen protection and gain deep-level privileged access to a phone via a USB connection.

Cellebrite UFED device.
A Cellebrite device used that is used to extract data from smartphones. Cellebrite

In this case, a tool offered by Cellebrite was reportedly used to unlock the phone of a Serbian student activist and gain access to data stored on it. Specifically, a Cellebrite UFED kit was deployed by law enforcement officials on the student activist’s phone, without informing them about it or taking their explicit consent.

Amnesty says the usage of a tool like Cellebrite — which has been abused to target journalists and activists widely — was not legally sanctioned. The phone in question was a Samsung Galaxy A32, while the Cellebrite device was able to break past its Lock Screen protection and gain root access.

“Android vendors must urgently strengthen defensive security features to mitigate threats from untrusted USB connections to locked devices,” says Amnesty’s report. This won’t be the first time that the name Cellebrite has appeared in the news.

Update your Android smartphone. ASAP!

The company sells its forensic analysis tools to law enforcement and federal agencies in the US, and multiple other countries, letting them brute-force their way into devices and extract critical information.

In 2019, Cellebrite claimed that it could unlock any Android or Apple device using its Universal Forensic Extraction Device. However, it has also raised ethical concerns and privacy alarms about unfair usage by authorities for surveillance, harassment, and targeting of whistleblowers, journalists, and activists.

A few months ago, Apple also quietly tightened the security protocols with iOS 18.1 update, with the intention of blocking unauthorized access to locked smartphones and preventing exfiltration of sensitive information.

Nadeem Sarwar
Nadeem is the Managing Editor at Digital Trends.
Leaked iPhone 18 Pro motherboard hints at Apple’s next cooling upgrade
A new motherboard image claims Apple is redesigning the A20 Pro's packaging for better thermal performance.
iPhone 18 Pro cameras

A fresh iPhone 18 Pro leak is making the rounds online, and it comes with some pretty bold claims. According to leaker Reptalicant, the alleged motherboard for Apple's upcoming flagship reveals a redesigned A20 Pro chip package with improved cooling, a beefier Neural Engine, and faster memory. That's a lot to unpack, especially considering motherboard-level Apple leaks like this are exceptionally rare.

The leak claims better thermals, faster memory, and a stronger NPU

Read more
Finding Android apps on the Google Play Store just got a lot easier thanks to Gemini
Google's AI assistant now works directly with the Play Store to recommend and install apps.
Google Play Store Photo

Google is making Gemini even more useful on Android. Google first previewed the Google Play connected app for Gemini at Google I/O 2026, and it's now finally rolling out to users. The new integration brings the Play Store directly into Gemini, letting the AI assistant help discover apps, make purchases, and complete more tasks without leaving the chat.

Gemini can now do more than recommend apps

Read more
It looks like Apple will treat you to a $200 price hike on the iPhone 18 Pro, after all
The Mac price hike told us a lot about what's coming for the iPhone 18 Pro, and IDC is now putting a number on it.
iPhone 17 Pro

Apple's Mac and iPad prices went up this week, by a good margin, no less, and the memory crisis behind them isn't going anywhere anytime soon. 

The obvious next question is what happens to the iPhone 18 Pro, which is expected to arrive later this year. IDC has an answer, and you might not like it (via MacRumors).

Read more