Techfullpost

Google fixes two Android zero-day vulnerabilities brought on by hackers

Android zero-day issues

Google released an Android update on Monday that resolves two zero-day bugs that “may be under limited, targeted exploitation,” as the company phrased it. That suggests Google is aware that hackers have and may continue to use the bugs to infect Android devices in real-world circumstances.

Amnesty International found one of the two now-fixed zero-days, tracked as CVE-2024-53197, in partnership with Benoît Sevens of Google’s Threat Analysis Group, the tech giant’s security division that analyzes government-backed cyberattacks. line by 75 days.

In February, Amnesty International discovered that Cellebrite, a firm that provides equipment to law enforcement for unlocking and forensically analyzing phones, was using a series of three zero-day vulnerabilities to hack into Android phones.

In this case, Amnesty discovered vulnerabilities, including one patched on Monday, that were being utilized against a Serbian student activist by local police armed with Cellebrite.

There isn’t much information available about the second vulnerability, CVE-2024-53150, which was patched on Monday, other than the fact that it was discovered by Google’s Sevens and that the bug was located in the kernel, an operating system’s core.

Google did not immediately respond to a request for comment.

Amnesty representative Hajira Maryam stated that the organization did not have anything to report at this time.

According to the tech giant’s alert, “the most severe of these issues is a critical security vulnerability in the System component that could lead to remote escalation of privilege with no additional execution privileges needed,” which means that “user interaction is not needed for exploitation.”

Google stated that it will release source code updates for the two corrected zero-days within 48 hours following the advisory, and that Android partners are “notified of all issues at least a month before publication.”

Given Android’s open source nature, every phone manufacturer must now distribute patches to their own consumers.

This item has been amended to reflect Amnesty’s response.

ADVERTISEMENT
RECOMMENDED
NEXT UP

Signal has rolled out a critical privacy-focused update for its Windows app, introducing a “screen security” setting that prevents the system from capturing screenshots—directly countering Microsoft’s controversial Recall feature.

This move reinforces Signal’s commitment to user privacy, ensuring sensitive conversations remain protected even against AI-powered background surveillance. Here’s everything you need to know.


Why Signal Is Blocking Windows Screenshots

Microsoft Recall: A Privacy Concern

Microsoft’s Recall feature (announced in 2023) continuously captures and stores screenshots of user activity, allowing Windows 11 users to “scroll back in time” and revisit past actions.

Despite Microsoft pausing Recall’s rollout after backlash, the company reintroduced it in April 2024 via the Windows Insider Preview Channel with key changes:
✔ Opt-in requirement (users must enable it manually)
✔ Pause functionality (temporary deactivation)

However, Signal argues that Recall still poses risks:
🔴 Potential exposure of sensitive chats (even if encrypted)
🔴 Lack of granular app-level control (Recall captures everything by default)

How Signal’s “Screen Security” Works

When enabled, this setting:
✅ Blocks Windows from screenshotting Signal’s window (shows a blank screen instead)
✅ Prevents Recall from storing private conversations
✅ Maintains end-to-end encryption integrity

⚠ Trade-off: Some accessibility tools (like screen readers) may not function properly with this setting active.


How to Enable (or Disable) Signal’s Screen Security

Step-by-Step Guide

  1. Open Signal Desktop
  2. Go to Settings > Privacy > Screen Security
  3. Toggle “Block screenshots” (enabled by default)

🔹 Disabling the feature requires confirmation (to prevent accidental deactivation).
🔹 A warning appears reminding users of potential privacy risks.


Signal’s Critique of Microsoft’s Approach

In a blog post, Signal expressed frustration with the need for such workarounds:

“We hope that AI teams building systems like Recall will consider these implications more carefully. Apps like Signal shouldn’t need a ‘one weird trick’ to protect user privacy—developers deserve better tools.”

Key Issues with Recall

🔸 No API for apps to opt out (forcing manual workarounds like Signal’s)
🔸 Potential security vulnerabilities (stored screenshots could be accessed by malware)
🔸 Privacy vs. convenience imbalance (users may not fully understand the risks)


What This Means for Windows Users

✔ Signal users gain stronger privacy protection against Recall.
✔ Other encrypted apps (like WhatsApp, Telegram) may follow suit.
✔ Microsoft faces continued scrutiny over AI-powered surveillance features.

Should You Disable Recall Entirely?

If privacy is a priority:

  1. Avoid enabling Recall (if using Windows Insider builds).
  2. Use Signal’s screen security for encrypted chats.
  3. Monitor future Windows updates for improved privacy controls.

Final Verdict: A Necessary Move for Privacy

Signal’s update highlights the growing tension between AI convenience and user privacy. While Microsoft positions Recall as a productivity tool, its always-on screenshotting raises legitimate security concerns.

By proactively blocking Recall, Signal sets a precedent—tech companies must prioritize privacy by design, not as an afterthought.

Saudi Crown Prince Mohammed bin Salman has made a strategic leap into artificial intelligence with the launch of Humain, a state-backed AI company poised to transform the Kingdom’s technological capabilities. This ambitious venture represents more than just another tech startup—it’s a cornerstone of Saudi Arabia’s Vision 2030 plan to diversify its oil-dependent economy and establish itself as a global AI leader.

Inside the Humain Initiative

Infrastructure Development

  • Massive data center construction across strategic Saudi locations
  • Cloud computing capabilities to rival global hyperscalers
  • AI research facilities with cutting-edge hardware

Financial Backing

  • Funded by Saudi Arabia’s $940 billion Public Investment Fund (PIF)
  • Part of broader $40 billion AI investment plan announced earlier this year
  • Positions Saudi Arabia as the world’s largest AI investor

The Geopolitical Context

High-Profile AI Summit Coincidence

The Humain launch coincides with a major U.S.-Saudi investment forum attracting tech titans:

  • Elon Musk (Tesla, xAI, SpaceX)
  • Sam Altman (OpenAI)
  • Mark Zuckerberg (Meta)
  • President Trump’s scheduled visit to the region

Strategic Partnerships

American tech giants are already engaging with Saudi’s AI ambitions:

  • Google’s cloud partnership with Saudi Aramco
  • Salesforce’s Middle East expansion
  • Microsoft’s $2.1 billion Saudi cloud investment

Why This Matters for Global Tech

1. Shifting AI Power Centers

Saudi Arabia’s move challenges traditional tech hubs, offering:

  • Alternative funding sources beyond Silicon Valley VCs
  • Geopolitical neutrality in US-China tech tensions
  • Energy advantages for power-intensive AI operations

2. Economic Transformation

The PIF’s strategy mirrors successful sovereign wealth plays:

  • SoftBank Vision Fund model at national scale
  • Norway’s oil fund approach applied to tech
  • Singapore’s Temasek -style strategic investing

3. Technology Sovereignty

Humain addresses critical national priorities:

  • Reducing dependence on foreign tech
  • Creating high-value domestic jobs
  • Securing data localization compliance

Challenges and Considerations

Potential Roadblocks

  • Talent acquisition in competitive global market
  • Cultural adaptation for international tech workers
  • Regulatory environment for AI development

Ethical Questions

  • AI governance in authoritarian context
  • Surveillance technology concerns
  • Content moderation approaches

What’s Next for Humain?

Industry analysts predict several likely developments:

  1. Major university partnerships for AI research
  2. Acquisition of niche AI startups
  3. Joint ventures with established tech firms
  4. Saudi-specific AI applications for:
    • Arabic language processing
    • Islamic finance technology
    • Smart city implementations

The Bigger Picture

This move positions Saudi Arabia at the center of three converging trends:

  1. The AI arms race among nations
  2. The petrodollar to tech-dollar transition
  3. Middle East’s emergence as a tech hub

With Humain, MBS isn’t just investing in AI—he’s attempting to future-proof Saudi Arabia’s economy and influence in what may become the most strategically important technology sector of the 21st century.

ADVERTISEMENT
Receive the latest news

Subscribe To Our Weekly Newsletter

Get notified about new articles