CVE-2024-29745: Android Pixel Information Disclosure Vulnerability
Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.
Other sources
there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of affected Android Pixel devices if vendor mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-29745?
CVE-2024-29745 is categorized as an information disclosure vulnerability.
How does CVE-2024-29745 affect users?
CVE-2024-29745 allows local information disclosure due to uninitialized data in the fastboot firmware.
How do I fix CVE-2024-29745?
To mitigate CVE-2024-29745, users should update their Android Pixel devices to the latest firmware version provided by Google.
Which devices are affected by CVE-2024-29745?
CVE-2024-29745 affects various Android Pixel devices utilizing the fastboot firmware.
Can CVE-2024-29745 be exploited remotely?
No, CVE-2024-29745 requires local access to exploit the information disclosure vulnerability.