Bad news for Samsung and Pixel users: your Android could be at risk right now according to Google reports
A new security warning has been issued for Samsung and Pixel users.


Google have confirmed once again that Android phones are under attack, marking yet another attempt at a breach in security in a short space of time.
The tech company, in a security bulletin, warned that “there are indications” that CVE-2024-53150 and CVE-2024-53197 “may be under limited, targeted exploitation“; interestingly, the latter was first brought to the company’s attention by Amnesty International.
Android’s report says that the first risk is a memory vulnerability within Android’s kernel, leaving a device exposed to local data exfiltration, with the language used particularly chilling: “the most severe vulnerability in this section could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation”, it writes.
CVE-2024-53150: heap overflow (read) in a Linux kernel USB sound card driver
— GrapheneOS (@GrapheneOS) April 7, 2025
CVE-2024-53197: heap overflow (write) in a Linux kernel USB sound card driver
These vulnerabilities were being exploited by Cellebrite for data extraction from locked Android devices without GrapheneOS.
Israeli company known for promoting phone surveillance
Cellebrite, a digital forensics company headquartered in Israel that provides tools for law enforcement, is said to have been exploiting the flaws in the Android code that many Pixel and Samsung users had installed. However, there are no details on who has been attacked, nor what information has been exploited.
GrapheneOS, an open-source security feature for Android users, wrote online that “Android Security Bulletin for April 2025 has 2 more vulnerabilities marked as being exploited in the wild”, adding that “GrapheneOS fully prevented exploiting both vulnerabilities for locked devices, made both far harder to exploit while unlocked and already had both patched for a while too.”
Android Security Bulletin for April 2025 has 2 more vulnerabilities marked as being exploited in the wild.
— GrapheneOS (@GrapheneOS) April 7, 2025
GrapheneOS fully prevented exploiting both vulnerabilities for locked devices, made both far harder to exploit while unlocked and already had both patched for a while too.
Related stories
On Monday, Google released an update for the wonky software, but that doesn’t stop people worrying about governments potentially trying to hack their devices and steal their data.
Get your game on! Whether you’re into NFL touchdowns, NBA buzzer-beaters, world-class soccer goals, or MLB home runs, our app has it all. Dive into live coverage, expert insights, breaking news, exclusive videos, and more – plus, stay updated on the latest in current affairs and entertainment. Download now for all-access coverage, right at your fingertips – anytime, anywhere.


Complete your personal details to comment