Amnesty International reported that Serbian authorities used Cellebrite forensic tooling to compromise the Android phone of a student activist, tying the intrusion to a zero-day exploit chain that enabled unauthorized access to the device. The findings expanded Amnesty’s broader documentation of digital surveillance and repression in Serbia, describing targeted mobile compromise as part of a wider campaign against civil society. Google Project Zero separately published technical research on a Qualcomm DSP driver exploit, adding detail on how Android exploitation chains can be built from low-level driver flaws.
Google later shipped Android security updates fixing 62 vulnerabilities, including two actively exploited zero-days, CVE-2024-53150 and CVE-2024-53197, both affecting Android kernel USB-audio ALSA drivers. Security advisories said the bugs could enable out-of-bounds memory reads, exposure of sensitive data, and privilege escalation, and noted reporting that CVE-2024-53197 had been used via Cellebrite tooling in the Serbian case. Defenders were urged to apply the 2025-04-05 Android security update immediately on affected devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Google released Android security updates addressing 62 vulnerabilities, including the actively exploited CVE-2024-53150 and CVE-2024-53197 in kernel USB-audio ALSA drivers. CSIRT.SK noted devices lacking the 2025-04-05 security update remained vulnerable and urged immediate patching.
Amnesty International Security Lab published a detailed account of a Cellebrite zero-day exploit used against the phone of a Serbian student activist, adding technical and investigative details about the attack chain.
Amnesty International reported that a Serbian student activist's Samsung Galaxy A32 was infected after Serbian police detained the activist and took the phone to a police station. The compromise chain included exploitation of Android USB kernel vulnerabilities via Cellebrite forensic tooling.
Amnesty International published its report "A Digital Prison," documenting surveillance and repression in Serbia, including forensic findings tied to exploitation of Android vulnerabilities and use of Cellebrite tooling against civil society targets.
Google Project Zero published technical research describing exploitation involving the Qualcomm DSP driver and how the exploit was excavated and analyzed. The post provided technical details that advanced public understanding of the exploit chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcesecuritylab.amnesty.org
Open sourceamnesty.org
Open sourcegoogleprojectzero.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.