EXPOSURES › CVE-2024-29748
CVE-2024-29748
HIGH ⌖ ON CISA KEV · EXPLOITEDAndroid Pixel devices allow attackers to bypass factory reset via a privilege escalation vulnerability.
CVE-2024-29748 enables attackers to interrupt factory resets on Android Pixel devices, potentially bypassing security controls during device initialization. This undermines the integrity of the device's security posture and could allow unauthorized access to sensitive data or system components.
Shame score — A privilege escalation vulnerability in a widely deployed consumer device that bypasses factory reset security controls.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.