ZeroHour

CVE-2024-29745

KEVmass

Uninitialized Data Information Disclosure in Google Pixel (Android)

CISA: Android Pixel Information Disclosure Vulnerability

CVSS 3.1
5.5 medium
EPSS
<1%p40
Published
()
KEV added
AI analysis

CVE-2024-29745 is an information disclosure vulnerability in Google Pixel devices running Android, caused by the use of uninitialized data (CWE-908), which can expose high-value memory contents. It is triggered locally: an attacker who already has low-privileged code on the device can trigger it with no additional execution privileges and no user interaction. The gain is leakage of confidential information (high confidentiality impact per the CVSS vector), which is especially valuable as a link in exploit chains; reporting indicates forensic tooling companies exploited Pixel zero-days, including this flaw, to unlock or extract data from devices. All users of Google Pixel devices on unpatched builds are in scope; the specific affected builds are enumerated in Google's Android security bulletin. Exploitation is confirmed in the wild — CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2024-04-04 (ransomware use: unknown) — while no public proof-of-concept is available.

What to do: Update Pixel devices to a patched security build — Google fixed this flaw in its March 2024 Pixel security update — and confirm each device's 'Android security update' patch level shows March 2024 or later. Prioritize remediation given the CISA KEV listing (added 2024-04-04) and confirmed in-the-wild use. As interim mitigation, limit untrusted local code execution on Pixel devices and restrict physical/USB access until patched.

Affected
Google Pixel smartphones running Android (CISA: Android Pixel)
Estimated exposure
masstens of millions of Pixel devices (estimated global active Pixel install base) — Pixel is Google's flagship Android phone line with an estimated active install base in the tens of millions, and the flaw resides in the devices' own software, so plausible exposure is bounded by that install base rather than by network…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CISA Known Exploited Vulnerability
Affected
Android Pixel
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
google
Products
android
Weakness
CWE-908
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news