Google Pixel Devices Exynos RIL Information Disclosure Vulnerability
Vulnerability
A possible out-of-bounds read vulnerability has been identified in the Exynos RIL component of Google Pixel devices. This issue arises from a missing bounds check in the ProtocolUnsolOnSSAdapter::GetServiceClass() function, which could lead to local information disclosure. Exploitation of this vulnerability requires a compromise of the baseband firmware, but does not need user interaction.
Impact
Exploitation of this vulnerability could result in unauthorized access to sensitive information, potentially leading to a compromise of the baseband firmware.
Remediation
Users can update their devices to the March 2025 security patch level to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
