Skip to content
COOEY

EXPOSURES › CVE-2024-29748

CVE-2024-29748

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-04-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-29748 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildprivilege-escalation

Android Pixel devices allow attackers to bypass factory reset via a privilege escalation vulnerability.

CVE-2024-29748 enables attackers to interrupt factory resets on Android Pixel devices, potentially bypassing security controls during device initialization. This undermines the integrity of the device's security posture and could allow unauthorized access to sensitive data or system components.

Shame score — A privilege escalation vulnerability in a widely deployed consumer device that bypasses factory reset security controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.