The vulnerability in question is tracked as CVE-2024-32896 and is described as an elevation of privilege (EoP) flaw. Last month, Google issued a Pixel security bulletin saying the exploit “may be under limited, targeted exploitation,” which in other words means that hackers are actively targeting affected devices. At the time, it was thought that only Pixel devices contained the flaw, but Google would later clarify that all Android devices are at risk.
That includes Galaxy handsets, and initially it was reported that a fix could take several months. However, Samsung apparently told Doffman that “the target scheduled for this fix is August,” with the caveat that the actual roll out “may vary on network provider and device.”
As to the vulnerability that’s been fast-tracked for a fix, there are still no fine grain details. That’s not unusual, as vendors like Google typically wait until a majority of affected users have access to a fix before spilling the beans, so as to keep hackers in the dark as long as possible.