Junglewise Threat Intelligence

CVE-2024-29745: Android Pixel Information Disclosure Vulnerability

CVE-2024-29745 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2024-04-04

Technologies: Android Pixel. Vendors: Android, Google.

Executive brief

Android Pixel devices contain an information disclosure vulnerability in the fastboot firmware due to uninitialized data. A local attacker can exploit this to access sensitive information without requiring additional execution privileges or user interaction.

Affected products

  • Google Pixel Fastboot firmware

Timeline

  • 2024-04-04: disclosed: NVD Published Date
  • 2024-04-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-04-01: advisory: Google Pixel Update Bulletin published

Related threats