CRITICAL🇵🇱 Wersja polska

CVE-2024-32911

CVSS 9.8v3.1pub. 2024-06-13upd. 2024-11-21

There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🤖 AI Analysis
How it works

The vulnerability lies in improper use of cryptography (CWE-327 — use of a broken or risky cryptographic algorithm, CWE-347 — improper verification of cryptographic signature). Incorrect implementation of cryptographic mechanisms may allow an attacker to bypass security measures based on integrity verification or data authenticity. Exploitation is possible remotely, without the need to possess additional privileges or engage the user.

Impact

An attacker can remotely obtain privilege escalation on a vulnerable Android device, potentially gaining full control over the system (confidentiality, integrity, and availability are fully threatened).

Mitigation & patch

Security patches available from the manufacturer should be applied in accordance with references — Pixel Security Bulletin published 2024-06-01 (https://source.android.com/security/bulletin/pixel/2024-06-01). Immediate software update of the device to the latest available version is recommended.

Who is affected

Google Android — versions indicated in manufacturer references (Pixel Security Bulletin from June 2024)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Google Android

    OS
    Google
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-16010CRITICAL9.6⚠ KEVPL ✓same product

Heap buffer overflow w Google Chrome na Android — sandbox escape

CVE-2016-1019CRITICAL9.8⚠ KEVPL ✓same product

Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku

CVE-2026-78937CRITICAL9.6same product

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...

CVE-2026-79129CRITICAL9.6same product

Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...

CVE-2026-79152CRITICAL9.8same product

Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...