Uninitialized Data Leads to Local Information Disclosure
Key Information
- Vendor
- Status
- Android
- Vendor
- CVE Published:
- 5 April 2024
Badges
Summary
Two critical zero-day vulnerabilities, CVE-2024-29745 and CVE-2024-29748, have been patched in Pixel smartphones by Google in the April 2024 security update. Forensic firms had been actively exploiting these vulnerabilities in the wild to extract personal data. CVE-2024-29745 allows information disclosure, while CVE-2024-29748 enables privilege escalation. The exploitation of these vulnerabilities could lead to unauthorized access and control over affected systems, highlighting the potential risk of data breaches and system compromise. It is recommended that all Pixel users update their devices to the latest security patch to mitigate these vulnerabilities.
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-29745 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
Android = Android kernel
News Articles
Samsung Issues Update Warning For Galaxy Smartphones As Google Confirms New Threat
Millions of Samsung Galaxy smartphones have a critical vulnerability with no fix…
5 months ago
Forensic Firms Exploit Pixel Android Zero Days - Spiceworks
Google has patched two zero-day vulnerabilities in Pixel smartphones that were being exploited by forensic firms. Find out more.
8 months ago
Google Pixel Phone Zero-days Exploited by Forensic Firms in the Wild : Patch Now
The Pixel Update Bulletin details security vulnerabilities and functional improvements for supported Pixel devices.
8 months ago
CVSS V3.1
Timeline
- 👾
Exploit exists.
Vulnerability started trending.
Vulnerability published.
First article discovered by Gizchina.com