Google Pixel phones have been compromised in zero-click attacks, a security vulnerability allowing attackers to gain access without user interaction. The attack method exploits previously unknown flaws in the device's systems.
A security analysis captured 72 hours of network traffic from three factory-default Google Pixel 8 phones using an external pfSense firewall and found that idle Android devices transmitted approximately 8,300 telemetry packets daily to Google servers, revealing location data, device fingerprints, notification heartbeats, photo sync tokens, and search queries without user interaction.
GrapheneOS accuses Google of withholding Android 17 QPR1 APIs and security fixes from other Android manufacturers and AOSP-based projects, claiming Google is gatekeeping features that were previously made available across the ecosystem. The project says it cannot release its own Android 17 QPR1 build without permission and that security patches affecting standard Android components won't reach other OEMs until December's QPR2 release.