ZeroHour

CVE-2024-32896

KEVmass

Local Privilege Escalation in Google Android Pixel Kernel

CISA: Android Pixel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p87
Published
()
KEV added
AI analysis

CVE-2024-32896 is a logic error (CWE-670/CWE-783) in Android code on Google Pixel devices that allows a bypass leading to local escalation of privilege. The flaw is triggered through local access with no additional execution privileges required, and user interaction is needed for exploitation to succeed. A successful attack yields high impact to confidentiality, integrity, and availability on the affected device (CVSS 3.1 base score 7.8), giving an attacker elevated control of the phone. Per CISA's advisory, only Google Pixel devices running Android are affected. The vulnerability is being exploited in the wild: it was added to CISA's KEV catalog on 2024-06-13, and news coverage describes limited, targeted exploitation of the Android kernel flaw as a zero-day, with users urged to install the latest security updates.

What to do: Apply the latest Android security updates from Google (June 2024 security patch level or later) to all Pixel devices, per vendor instructions and CISA's required action. Users can verify their patch level under Settings > About phone > Android security update. Given reports of limited, targeted zero-day exploitation, prioritize patching high-risk users and treat the flaw as a post-compromise privilege-escalation risk.

Affected
google Android (Pixel)
Estimated exposure
masstens of millions of Pixel devices (estimated active Pixel install base; exact count unknown) — Pixel is estimated at roughly 2% of the multi-billion-device Android install base, implying tens of millions of active devices, though Google does not publish exact figures.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CISA Known Exploited Vulnerability
Affected
Android Pixel
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
google
Products
android
Weakness
CWE-670, CWE-783
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news