Google just fixed 46 security flaws, including an actively exploited zero-day — update your Android phone now

Google Pixel 8 shown held in hand
(Image credit: Tom's Guide)

Google released this month’s Android security updates, which contain patches for 46 different vulnerabilities, including one actively exploited zero-day flaw.

As reported by BleepingComputer, the zero-day in question (tracked as CVE-2024-36971) is a use after free vulnerability in the Linux kernel used by Android for controlling network route management. 

While exploiting this security flaw requires System execution privileges, Google explained in an Android security bulletin that there are indications that this zero-day “may be under limited, targeted exploitation.” Successful exploitation would allow hackers to execute arbitrary code on unpatched devices without user interaction.

This zero-day was discovered by Google’s own Clément Lecigne, a security researcher for the search giant’s Threat Analysis Group (TAG). As is often the case, though, the company has not provided details on how this flaw is being exploited to give owners of the best Android phones time to patch their devices.

Still, though, security researchers at Google’s TAG are often responsible for finding and disclosing zero-day flaws that state-sponsored hackers use in attacks targeting high-profile individuals such as CEOs, politicians and activists. 

How to update your Android smartphone

Android 14

(Image credit: Tom's Guide)

To address this zero-day and 45 other security flaws, Google has released two sets of patches as part of its August security updates in the form of 2024-08-01 and 2024-08-05. The second patch set includes all the fixes from the first and additional patches for third-party closed-source and Kernel components.

While Google’s Pixel phones get the latest security updates as soon as they’re released, the best Samsung phones and devices from other popular hardware makers could take additional time to start rolling them out to users.

To see if an update is available for your Android phone, you can head to Settings and look for System, Software Update or About Phone, depending on your phone’s manufacturer. From there, tap System update or Software update and then tap Check for update. If an update is available, you can download and install it onto your phone. However, you’re going to want to make sure that your device is charged and connected to Wi-Fi before proceeding with installing any updates. If you need extra help, check out our guide on how to update Android.

Even though the zero-day flaw described above may be under active exploitation by hackers, it’s only being used in targeted attacks, which means that most Android users are likely safe from threats. Still, this is a great reminder to ensure your smartphone is running the latest software.

More from Tom's Guide

TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
How to disable the Windows key
Microsoft patches over 160 security flaws including 3 active zero days — update your PC right now
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Latest in Android Phones
Google Pixel 9 with Amazon Spring Sale deal tag
The Google Pixel 9 is at its lowest price ever for Amazon Spring Sale — 30% off now
Amazon Spring Sale Galaxy S25
Amazon’s Spring Sale drops the Samsung Galaxy S25 to $734 — its lowest price ever!
OnePlus 13 back, leaning against blue wall
OnePlus 13T could come with an even bigger battery than OnePlus 13 — this is incredible
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Android 16 screen-off fingerprint unlock in Settings menu
Android 16's latest beta lets all Pixel users unlock their phone more easily — here’s how
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Latest in News
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours
A TV with the Netflix logo sits behind a hand holding a remote
Netflix is rolling out a big video quality upgrade — what you need to know
Choi Hyun-Wook, Hong Kyung, and Park Ji-hoon in "Weak Hero Class 1" now streaming on Netflix
This action-packed K-drama is now streaming on Netflix — and now’s the time to binge-watch before season 2