Jump to content
Facebook Twitter Youtube

[Gadgets] Google Pixel Bug That Allowed Bypassing the Lock Screen Fixed With November Update


Angrry.exe™
 Share

Recommended Posts

google_pixel_6_image_2_1634717738572.jpg

Google Pixel phones were recently updated with a fix for a security flaw that allowed a user to bypass the lock screen, after it was reported by a security researcher. The company announced earlier this week that it had begun globally rolling out the November Android update for the Pixel smartphones running on Android 13. This update will be made available to Pixel users gradually over the next few weeks. Apart from bringing fixes and improvements, this update also includes the November 2022 Android security patch, which includes a bug fix that resolves a security issue that allows people to bypass the lock screen using a SIM card.

Security researcher David Schütz discovered a security flaw, tracked as CVE-2022-20465 in the November 2022 Android security patch update. It allowed an attacker with physical access to a Pixel smartphone to bypass lock screen security measures such as fingerprint, PIN, and pattern.

Schütz demonstrated the bug on the Pixel 6, which allowed people to bypass the biometrics by swapping out the SIM card and entering the SIM PIN incorrectly three times. The device would then ask for the Personal Unlocking Key (PUK) code.

Entering the PUK code correctly, the phone would ask for a new PIN code for that SIM card. The handset would then unlock and take users to the home screen with full access to the device.

Schütz had reported this bug to Google via the Android Vulnerability Rewards Program. After waiting for a few months, he was rewarded with $70,000 (roughly Rs. 56,57,000) for spotting the security flaw. It is now [listed] in the November security patch as a High severity system issue. It has also been included in the Android Open Source Project (AOSP) version of Android 10, 11, 12, 12L, and 13.

https://www.gadgets360.com/mobiles/news/google-pixel-bug-lock-screen-bypass-fix-november-android-update-3510934

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

WHO WE ARE?

CsBlackDevil Community [www.csblackdevil.com], a virtual world from May 1, 2012, which continues to grow in the gaming world. CSBD has over 70k members in continuous expansion, coming from different parts of the world.

 

 

Important Links