EXPOSURES › CVE-2024-29745
CVE-2024-29745
HIGH ⌖ ON CISA KEV · EXPLOITEDAndroid Pixel fastboot firmware leaks sensitive data during device unlocking and flashing, enabling unauthorized access to device secrets.
This information disclosure vulnerability in Android Pixel's fastboot firmware allows attackers to extract sensitive data during the unlocking and flashing process, posing a significant risk to device security and compliance. DIB organizations must ensure their Android devices are patched and avoid using unpatched fastboot firmware to prevent potential data exfiltration and unauthorized access.
Shame score — A known information disclosure vulnerability in fastboot firmware that was actively exploited but did not involve remote code execution or default credentials.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.