Skip to content
COOEY

EXPOSURES › CVE-2021-39793

CVE-2021-39793

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-39793 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatched

A local privilege escalation vulnerability in Google Pixel devices was actively exploited in the wild, highlighting the risks of unpatched hardware in defense supply chains.

An out-of-bounds write vulnerability in Google Pixel devices allowed local privilege escalation, and it was listed in CISA's KEV catalog, indicating active exploitation. DIB organizations must ensure hardware and firmware are patched before deployment to prevent attackers from leveraging known vulnerabilities for lateral movement or data exfiltration. This failure underscores the need for rigorous supply-chain vetting and continuous patch management for mobile devices accessing classified networks.

Shame score — The vulnerability was actively exploited in the wild and included in CISA's KEV catalog, demonstrating that known flaws in consumer hardware can be weaponized against enterprise environments if not patched.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized