Google's Threat Analysis Group (TAG) warns of a Samsung zero-day vulnerability, tracked as CVE-2024-44068 (CVSS score of 8.1), which is exploited in the wild.
The vulnerability is a use-after-free issue, where attackers could exploit the flaw to escalate privileges on a vulnerable Android device.
Samsung addressed the vulnerability with the release of security updates in October 2024.
The fact that Google TAG discovered the flaw suggests that commercial spyware vendors may have used the exploit to target Samsung devices.