Pixel phones are known for their strong security features, particularly in protecting the cellular baseband, which is the processor handling LTE, 4G, and 5G communications. While basebands in smartphones are often vulnerable to attacks due to performance constraints, Pixel has implemented security hardening measures for years. Google claims that the Pixel 9 implements the most secure baseband to date, addressing a critical attack vector exploited by researchers.
The cellular baseband manages a smartphone’s network connectivity and processes external inputs, including those from untrusted sources. In the past, researchers documented multiple attacks relying on false base stations<\/a> to target mobile devices. Threat actors can remotely carry out these kinds of attacks through protocols like IMS. <\/p>\n\n\n\n
“malicious actors can\u00a0employ false base stations to inject fabricated or manipulated network packets<\/a>. In certain protocols like IMS (IP Multimedia Subsystem), this can be executed remotely from any global location using an IMS client.” reads Google’s announcement<\/a>.<\/em><\/p>\n\n\n\n
Experts warn that most smartphone basebands lack exploit mitigations commonly used in software development. Zero-day brokers and commercial spyware vendors<\/a> can exploit these vulnerabilities to target mobile users and deploy malware like Predator<\/a>. Baseband exploits are frequently listed in exploit marketplaces with low payouts, indicating their abundance. In response, Android and Pixel have strengthened their Vulnerability Rewards Program, prioritizing the identification and resolution of connectivity firmware vulnerabilities.<\/p>\n\n\n\n
Additionally, bug detection tools like address sanitizer<\/a> are used during testing to patch bugs before shipping.<\/p>\n\n\n\n
Pierluigi Paganini<\/strong><\/a><\/p>\n\n\n\n
Follow me on Twitter: @securityaffairs<\/strong><\/a> and Facebook<\/strong><\/a> and Mastodon<\/a><\/p>\n\n\n\n
(<\/strong>SecurityAffairs<\/strong><\/a>\u00a0\u2013<\/strong>\u00a0hacking, Google Pixel)<\/strong><\/p>\n\n\n\n