INCIDENT EVIDENCE GRAPH
Google confirms spyware attacks exploiting a Pixel zero-day vulnerability, mainly targeting high-value targets with zero-click attacks
#Security News Google confirmed that spyware exploited a Pixel zero-day vulnerability to launch attacks, mainly targeting high-value targets with zero-click attacks. The vulnerability is located in Pixel modem firmware, and attackers can exploit it to escape the sandbox and escalate privileges. Google is willing to pay a $200,000 bounty for a zero-click vulnerability; instead of submitting the vulnerability to claim the bounty, hackers developed spyware, showing how profitable such illicit activity can be. Read more: https://ourl.co/126908
- Victim: High-value targets
- Actor: Spyware operators
- Exploit: Pixel modem firmware zero-day vulnerability
- Method: Zero-click attack enabling sandbox escape and privilege escalation