Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unneeded on pixel devices per the project zero announcement [0]:

> affected Pixel devices have already received a fix for CVE-2023-24033 in the March 2023 security update

[0] https://googleprojectzero.blogspot.com/2023/03/multiple-inte...



I am still running the February update on my Pixel 6. When I check for updates, I don't see one.


+1, no March update on pixel 6a yet


Chiming in to say the same thing.


+1 too.


But some Pixel phones haven't gotten the March 2023 security update yet, per the article.


[flagged]


Let me clarify: it's not that some Pixel owners just haven't installed the March update yet. It's that Google hasn't released it it for some Pixel models.


Is there any way to mitigate VoLTE on Pixel 6?

I see I can turn off Wi-Fi calling (which I did long ago because it never worked), but no toggle and no march update available.


I believe switching the "preferred network" back to 3G (in the SIM settings) does this. VoLTE is 4G/5G.


Google has not released the March update for Pixel 6, 6 Pro, and 6a.


Hang on - if I understand correctly, all of the following is true for Pixel 6, Pro, and 6a users??

- There's an exploit out there that lets attackers own my phone if they know my number

- A patch is not available for my phone yet

- It's not possible to work around the issue because a previous update removed the toggle

- Announcing this signals to every competent black hat worth their salt to begin looking for exploits on this chipset, knowing the reward is high and the method of pulling it off is implied to be simple

I really wish Google had delayed this blog post until after all of their currently supported flagship products were no longer affected...


> I really wish Google had delayed this blog post until after all of their currently supported flagship products were no longer affected

Aren't they legally required to disclose security vulnerabilities like this within a certain time limit?

Seems like the real anger should be directed at them removing the toggle to turn it off.


I don’t think they’re legally required to do so. However they have a very aggressive publication schedule and selectively making exceptions for Google and not for competitors would look terrible, and possibly expose them to lawsuits.


Some mobile careers no longer operate 3G so turn off VoLTE isn't an option for some people. Google must release patch before this.


Under what law?


This was patched in other models so that gives a head start for people who reverse-engineer such things.

As for Samsung, their March 2023 patch closes items that sound similar. [1]

[1] https://www.sammyfans.com/2023/03/06/samsung-march-2023-secu...


And then everyone here would attack Google for covering up their own vulnerabilities.

This is a sign of integrity.


[flagged]


That’s pretty funny. I just bought a pixel 6a with the intent of replacing my iPhone. About an hour of “how the hell do people put up with this shit” and it’s going. Then I wake up to this.


As a point of comparison a recently inherited a ton of Apple gear and I've been swearing at it in a similar fashion fairly regularly.


Oh I have exactly the same trouble. I’m in the middle of moving back to windows


Switching OS always takes time to adjust. I have the same feeling any time I try to use a Mac or iPhone.


Your brain definitely gets trained on one system and moving off hurts. Hell, I've had my work Macbook for 5 years and I still curse the keyboard shortcuts that are all wrong (and the even more shortcuts that it's missing).


> affected Pixel devices have already received a fix for CVE-2023-24033 in the March 2023 security update

That line is carefully deceptive (lawyerly, even). Pixel 6 series have not yet received the March 2023 update.


The patch was written but withheld due to bugs. So you are not patched yet.


Hi Matthew, could you provide a source? I thought the fix was already being rolled out (or about to get rolled out for the Pixel 6).


Yes I think it was a week late but is now being rolled out. People on Twitter are saying they don’t have it yet, which is the nature of individual experience.

https://9to5google.com/2023/03/06/march-google-pixel-update-...


Google Support said that the Pixel 6 series won't be updated until March 20. This seems horrific to me.


Today is March 23rd. There has been no pixel 6 update since March 5



That is only for CVE-2023-24033 thought, right? Not the other three that haven't been assigned CVE ID's?

> The four most severe of these eighteen vulnerabilities (CVE-2023-24033 and three other vulnerabilities that have yet to be assigned CVE-IDs) allowed for Internet-to-baseband remote code execution.


Ah, that would explain the multiple patches that came in last week on my 7 Pro. I thought it was strange.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: