High - CVSS 7.5
Added 6/13/2024

Android Pixel Privilege Escalation Vulnerability

CVE-2024-32896
Action was due by: 7/4/2024
CISA Known Exploited Vulnerability

This vulnerability is part of CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.

Overview

Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.

Vendor

Android

Product

Pixel

Category

Software
Technical Details

Affected Versions

See vendor advisory

Technical Description

This vulnerability was identified in Pixel by Android. Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.

Exploitability

Medium - Publicly disclosed

Impact

Significant security impact

Additional Notes

https://source.android.com/docs/security/bulletin/pixel/2024-06-01; https://nvd.nist.gov/vuln/detail/CVE-2024-32896

Required Action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due Date: 7/4/2024