Google's Project Zero security research team has exposed critical Exynos chipset flaws — 18 vulnerabilities found inside Samsung's Exynos processor that could allow hackers to remotely seize control of your phone, smartwatch, or even your car, without any interaction from you.
What Are the Exynos Chipset Flaws Google Discovered?
Google's Project Zero, one of the world's most respected security research teams, identified a total of 18 security vulnerabilities within Samsung's Exynos chipsets. Team lead Tim Willis confirmed that four of these 18 flaws are especially dangerous: they can be exploited by attackers to remotely take over a device using only the victim's phone number. No clicks, no downloads, no user action required.
The remaining 14 vulnerabilities are considered less immediately threatening, but they are still serious. Exploiting them would require access to a malicious or compromised mobile network — something that is not beyond the reach of a determined attacker.
Which Devices Are Affected by the Exynos Security Vulnerabilities?
The scope of affected hardware is wide. Samsung's own devices make up the largest group, but the problem extends to phones from other brands and even to vehicles.
- Samsung phones: Galaxy S22, M33, M13, M12, A71, A53, A33, A21s, A13, A12, and A04 series
- Vivo phones: S16, S15, S6, X70, X60, and X30 series
- Google phones: Pixel 6 and Pixel 7 series
- Vehicles: Cars equipped with the Exynos Auto T5123 chipset
Samsung's Exynos chipset is widely embedded across mobile devices, smartwatches, and connected cars, which is why the blast radius of these flaws is so unusually large.
How to Protect Your Phone Right Now
Until Samsung and affected device makers release security patches, there are two immediate steps you can take to reduce your exposure to these Exynos chipset flaws:
- Turn off Wi-Fi Calling on your device. This feature uses the internet to route phone calls and is one of the attack vectors the four most critical vulnerabilities exploit.
- Disable VoLTE (Voice over LTE). Like Wi-Fi calling, VoLTE is a potential entry point for remote exploitation.
Both settings are typically found under your phone's Calls or Mobile Network settings. Disabling them reduces functionality slightly but removes the primary surface through which a remote attacker could target your device without any interaction from you.
Why This Matters Beyond Samsung
What makes this disclosure particularly significant is that it implicates Google's own Pixel devices. Google's Project Zero team found and reported the vulnerabilities — and Google's own Pixel 6 and Pixel 7 phones, which also use Exynos modems in certain configurations, are on the affected list. This is a rare case where the team discovering the flaw also makes a product vulnerable to it.
The involvement of the Exynos Auto T5123 chipset used in vehicles also marks an expansion of the threat surface beyond consumer smartphones into connected automotive systems, highlighting how pervasive chipset-level vulnerabilities can be across modern technology ecosystems.
What Happens Next
Google's Project Zero operates under a responsible disclosure policy, typically giving vendors 90 days to issue a patch before full technical details are made public. Samsung is expected to address these vulnerabilities through its regular monthly security update cycle. Users on affected devices should watch for incoming software updates and install them as soon as they become available. In the meantime, keeping Wi-Fi Calling and VoLTE switched off remains the most practical short-term defence against the four most critical Exynos chipset flaws.