Vulnerabilities

CISA Warns of Pixel Phone Vulnerability Exploitation

CISA adds Pixel Android phone (CVE-2023-21237) and Sunhillo SureLine (CVE-2021-36380) flaws to its known exploited vulnerabilities catalog. 

The US cybersecurity agency CISA on Tuesday added flaws impacting Pixel phones and Sunhillo software to its Known Exploited Vulnerabilities (KEV) catalog. 

The exploited Pixel vulnerability is tracked as CVE-2023-21237. When it patched the flaw in June 2023, Google warned that it had been aware of “limited, targeted exploitation”, but the company published its security bulletin for Pixel phones a week after the general Android security bulletin and CVE-2023-21237 went unnoticed. 

CVE-2023-21237 impacts the Framework component and is related to hiding foreground service notifications due to a misleading or insufficient UI. An attacker could exploit it to obtain sensitive information without the need for additional execution privileges or user interaction.

There does not appear to be any public information on the exploitation of the vulnerability. However, it may be part of an exploit chain used by a commercial spyware vendor to hack Pixel Android phones. 

The second vulnerability added by CISA to its KEV list on Tuesday is CVE-2021-36380, which impacts Sunhillo SureLine. Sunhillo provides surveillance data distribution and conversion products for the aviation industry, and SureLine is described as the backbone of the company’s  surveillance gateway products. 

CVE-2021-36380 was disclosed and patched in the summer of 2021. NCC Group, whose researchers discovered the vulnerability, described the flaw as a critical unauthenticated OS command injection issue that could allow an attacker to take complete control of the targeted system.

Advertisement. Scroll to continue reading.

In November 2023, SonicWall reported seeing attempts to exploit the SureLine product vulnerability in its honeypots. The cybersecurity firm determined that the exploitation attempts were likely associated with the Mirai botnet, which ensnares a wide range of IoT devices and abuses them for DDoS attacks.

CISA has added the Pixel and SureLine vulnerabilities to its KEV catalog and instructed federal agencies to address them by March 26. While government organizations are required by a binding operational directive to address flaws added to the KEV list, all organizations are urged to use the resource for vulnerability prioritization.

Related: CISA Warns of Roundcube Webmail Vulnerability Exploitation

Related: CISA Warns of Windows Streaming Service Vulnerability Exploitation

Related: CISA Urges Patching of Cisco ASA Flaw Exploited in Ransomware Attacks

Related Content

Vulnerabilities

The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.

Vulnerabilities

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.

Vulnerabilities

Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.

Vulnerabilities

The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.

Vulnerabilities

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.

Vulnerabilities

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.

Vulnerabilities

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

Vulnerabilities

The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version