{"id":169402,"date":"2024-10-06T08:44:36","date_gmt":"2024-10-06T08:44:36","guid":{"rendered":"https:\/\/securityaffairs.com\/?p=169402"},"modified":"2024-10-06T08:44:39","modified_gmt":"2024-10-06T08:44:39","slug":"google-pixel-9-mitigates-baseband-attacks","status":"publish","type":"post","link":"https:\/\/securityaffairs.com\/169402\/security\/google-pixel-9-mitigates-baseband-attacks.html","title":{"rendered":"Google Pixel 9 supports new security features to mitigate baseband attacks"},"content":{"rendered":"
<\/div>\n

Google announced that its Pixel 9 has implemented new security features, and it supports measures to mitigate baseband attacks.<\/h2>\n\n\n\n

Pixel phones are known for their strong security features, particularly in protecting the cellular baseband, which is the processor handling LTE, 4G, and 5G communications. While basebands in smartphones are often vulnerable to attacks due to performance constraints, Pixel has implemented security hardening measures for years. Google claims that the Pixel 9 implements the most secure baseband to date, addressing a critical attack vector exploited by researchers. <\/gwmw><\/p>\n\n\n\n

The cellular baseband manages a smartphone’s network connectivity and processes external inputs, including those from untrusted sources. In the past, researchers documented multiple attacks relying on false base stations<\/a> to target mobile devices. Threat actors can remotely carry out these kinds of attacks through protocols like IMS. <\/p>\n\n\n\n

“malicious actors can\u00a0employ false base stations to inject fabricated or manipulated network packets<\/a>. In certain protocols like IMS (IP Multimedia Subsystem), this can be executed remotely from any global location using an IMS client.” reads Google’s announcement<\/a>.<\/em><\/p>\n\n\n\n

Baseband firmware can be affected by vulnerabilities, making it a significant attack vector. Exploiting baseband bugs can lead to remote code execution.<\/p>\n\n\n\n

Experts warn that most smartphone basebands lack exploit mitigations commonly used in software development. Zero-day brokers and commercial spyware vendors<\/a> can exploit these vulnerabilities to target mobile users and deploy malware like Predator<\/a>. Baseband exploits are frequently listed in exploit marketplaces with low payouts, indicating their abundance. In response, Android and Pixel have strengthened their Vulnerability Rewards Program, prioritizing the identification and resolution of connectivity firmware vulnerabilities.<\/p>\n\n\n\n

Pixel has added proactive defenses over the years, key security measures implemented in the Pixel 9 series include:<\/p>\n\n\n\n