Google Project Zero security researcher Maddie Stone said in a blog post that the exploit chain targets Samsung phones with a Exynos chip running a specific kernel version.The flaws, since patched, were exploited by a malicious Android app, which the user may have been tricked into installing from outside of the app store.The malicious app allows the attacker to escape the app sandbox designed to contain its activity, and access the rest of the device’s operating system.Stone said that Samsung has since committed to begin disclosing when vulnerabilities are actively exploited, following Apple and Google, which also disclose in their security updates when vulnerabilities are under attack.“The analysis of this exploit chain has provided us with new and important insights into how attackers are targeting Android devices,” Stone added, intimating that further research could unearth new vulnerabilities in custom software built by Android device makers, like Samsung."