Google warns of an actively exploited Android kernel flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-32896 | Local Privilege Escalation in Google Android Pixel Kernel CVE-2024-32896 is a logic error (CWE-670/CWE-783) in Android code on Google Pixel devices that allows a bypass leading to local escalation of privilege. The flaw is triggered through local access with no additional execution privileges required, and user interaction is needed for exploitation to succeed. A successful attack yields high impact to confidentiality, integrity, and availability on the affected device (CVSS 3.1 base score 7.8), giving an attacker elevated control of the phone. Per CISA's advisory, only Google Pixel devices running Android are affected. The vulnerability is being exploited in the wild: it was added to CISA's KEV catalog on 2024-06-13, and news coverage describes limited, targeted exploitation of the Android kernel flaw as a zero-day, with users urged to install the latest security updates. Do: Apply the latest Android security updates from Google (June 2024 security patch level or later) to all Pixel devices, per vendor instructions and CISA's required action. Users can verify their patch level under Settings > About phone > Android security update. Given reports of limited, targeted zero-day exploitation, prioritize patching high-risk users and treat the flaw as a post-compromise privilege-escalation risk. | 7.8 | 3% | KEV |
| masstens of millions of Pixel devices (estimated active Pixel install base; exact count unknown) | |
| CVE-2024-36971 | Use-after-free in Linux kernel network dst cache (CVE-2024-36971), exploited on Android CVE-2024-36971 is a use-after-free (CWE-416) race condition in the Linux kernel networking stack: __dst_negative_advice() clears a socket's cached destination (sk->sk_dst_cache) in the wrong order relative to RCU rules and dst_release(), which can free the destination entry while it is still referenced. The bug is reachable through UDP socket operations, and CISA catalogs the impact as remote code execution in the affected kernel (Android Kernel), although the published CVSS 3.1 vector scores a local attack vector (7.8 High, AV:L). An attacker who triggers the race gains code execution in kernel context, meaning on Android a malicious app could potentially escape its sandbox and take full control of the device, with high impact on confidentiality, integrity, and availability. Affected systems include Android devices running vulnerable kernels and Linux-based systems listed in the CPE data (upstream Linux kernel and Debian Linux), with no specific vulnerable version ranges disclosed in the available data. The flaw is being actively exploited: Google warned of in-the-wild exploitation (the issue was tracked by researcher Clement Lecigne), CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-07, and EPSS estimates a ~2.7% probability of exploitation in the next 30 days; no public PoC is known. Do: Install Android security updates from Google and device OEMs (Google has already shipped patches) and verify your device's security patch level is current. Debian and other Linux users should update kernel packages to builds containing the upstream fix for the __dst_negative_advice() race. Because CISA added this to KEV on 2024-08-07 with active exploitation, apply vendor mitigations promptly or discontinue use if mitigations are unavailable. | 7.8 | 3% | KEV |
| masson the order of billions of Android devices potentially affected pre-patch (upper bound), plus a large installed base across Linux/Debian systems |
Full article354 words · extracted from securityaffairs.com · click to collapse

Google addressed an actively exploited high-severity vulnerability, tracked as CVE-2024-36971, impacting the Android kernel.
Google fixed a high-severity flaw, tracked as CVE-2024-36971, impacting the Android kernel. The IT giant is aware that the vulnerability has been actively exploited in the wild. The company did not share details of the attacks exploiting this vulnerability.
The vulnerability is a remote code execution impacting the kernel.
“There are indications that CVE-2024-36971 may be under limited, targeted exploitation.” reads the advisory published by Google.
The vulnerability was discovered by Clement Lecigne of Google’s Threat Analysis Group (TAG). The TAG team investigates attacks carried out by nation-state actors and commercial spyware vendors.
Android Security Bulletin for August 2024 addressed a total of 47 vulnerabilities in Framework (13), System (1), Kernel (1), Arm components (2), Imagination Technologies (1), MediaTek components (1), Qualcomm components (21), and Qualcomm closed-source components (7).
The vulnerabilities addressed by Google include Elevation of Privileges, DoS, Remote Code Execution, and Information disclosure.
“The most severe of these issues is a high security vulnerability in the Framework component that could lead to local escalation of privilege with no additional execution privileges needed.” continues the advisory.
In June 2024, Google warned of an elevation of privilege vulnerability, tracked as CVE-2024-32896, in the Pixel Firmware, which has been exploited in the wild as a zero-day.
“There are indications that CVE-2024-32896 may be under limited, targeted exploitation.” reads the advisory.
As usual, the IT giant did not provide technical information about attacks exploiting the above issue.
The Pixel Update Bulletin provides details of security vulnerabilities and functional improvements for supported Google Pixel devices. The company addressed all the flaws detailed in the bulletin with the release of the security patch levels of 2024-06-05 or later and the June 2024 Android Security Bulletin.
In June 2024, Google warned of an elevation of privilege vulnerability, tracked as CVE-2024-32896, in the Pixel Firmware, which has been exploited in the wild as a zero-day.
“There are indications that CVE-2024-32896 may be under limited, targeted exploitation.” reads the advisory.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Android)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/166656/breaking-news/google-actively-exploited-android-kernel-flaw.html