Google finds 18 zero-day vulnerabilities in Samsung Exynos chipsets

TL;DR

Project Zero, Google's zero-day bug-hunting team, discovered and reported 18 zero-day vulnerabilities in Samsung’s Exynos chipsets used in mobile devices, wearables, and cars. These Internet-to-baseband remote code execution (RCE) bugs (including CVE-2023-24033 and three others still waiting for a CVE-ID) allow attackers to compromise vulnerable devices remotely and without any user interaction. "Related Articles:CISA warns of actively exploited Plex bug after LastPass breachCISA warns of critical VMware RCE flaw exploited in attacksFortinet warns of new critical unauthenticated RCE vulnerabilityProof-of-Concept released for critical Microsoft Word RCE bug

Like summarized versions? Support us on Patreon!