HIGH🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-32896

CVSS 7.8v3.1pub. 2024-06-13upd. 2025-10-24

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Google Android

    OS
    Google
    all versions

CISA KEV — detailsi

Vendori
Android
Producti
Pixel
Added to KEVi
June 13, 2024
Remediation deadline (US Federal)i
July 4, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 4 lipca 2024
CWE
References

Related vulnerabilities

CVE-2020-16010CRITICAL9.6⚠ KEVPL ✓same product

Heap buffer overflow w Google Chrome na Android — sandbox escape

CVE-2016-1019CRITICAL9.8⚠ KEVPL ✓same product

Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku

CVE-2026-78937CRITICAL9.6same product

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...

CVE-2026-79129CRITICAL9.6same product

Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...

CVE-2026-79152CRITICAL9.8same product

Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...