Saltar al contenido
SoftwaresCRM 馃寪 Guides for learning to surf the Android

the story of a hacker and his performance in front of Google

An ethical pirata informático has discovered a vulnerability affecting all Google plus Pixels, allowing users to easily bypass the lock screen.

"This is how I made $70,000 for finding a bug": The story of a hacker and his performance before Google
The Pixel 7 is one of the teléfonos inteligentes we analyzed at Andro4all in October 2022 / Image: Christian Collado

With the analysis of the Pixel 7 still quite fresh and some time having passed since its official presentation, there will still be people who will wonder if Google plus devices offer a lot to talk about. In this case, by the way, we are not focusing on a new terminal or other Mountain View hardware.

News has reached us that a pirata informático has discovered a green screen bug affecting all Google plus Pixels. That’s important in itself, but what’s really strange about the news is that by discovering this vulnerability, the pirata informático Won $70,000 As a reward.

An accident worth a lot of money

The pirata informático himself, a white hat (or “ethical pirata informático”) named David Schultz, he has published an extensive article in his personal blog Reporting their results and communicating with Google plus. The discovery was made purely by accident when Schultz sent a message and his Pixel 6 ran out of battery.

Next thing he did was plug it in, charge it up and turn it on. The phone then asked for the PIN code of the SIM card to start. After three incorrect entries, the SIM was blocked and asked for the PUK code, after which he could entrar a new PIN. But then he came to the green screen something was wrong.

From here, the pirata informático decided to investigate further. Repeating the situation several times, he found to his surprise that he had found something that allowed everyone bypass the lock screen easily. All that is required is physical access to the phone, the SIM lock and the SIM card removal tool. See the fallo in action on vídeo below:

After Schultz confirmed the vulnerability on his phone, he repeated the process using a Pixel 5. To his surprise the bug also worked on this phone. Next they contacted Google plus who gave the above $70,000 as the second person to send them this decision.

Furthermore, Google plus has already solved the problem. The November Android security update fixes this vulnerability so you don’t have to worry about it after installing it.

Configuration