LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-29745: Android Pixel Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 4, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 25, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-29745 to its Known Exploited Vulnerabilities catalog on Apr 4, 2024, with a federal patch deadline of Apr 25, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.

CVE-2024-29745 is an information disclosure vulnerability affecting Android Pixel devices. It resides in the fastboot firmware that supports unlocking, flashing, and locking those devices. For IT and security teams managing Pixel fleets, the issue matters because successful abuse can leak sensitive data that should remain protected, increasing risk of further compromise if an attacker already has a foothold or physical access path.

Public detail is limited to the CISA description and the associated weakness class. Confirm exact impact, affected builds, and remediation steps against the vendor advisory before treating any device as safe or unsafe.

How it works

The vulnerability is classified under CWE-908 (Use of Uninitialized Resource). In this class of flaw, code paths that handle a resource—here, within the fastboot firmware used for device unlock, flash, and lock operations—fail to properly initialize memory or state before it is read or exposed. An attacker who can interact with the affected firmware interface may obtain residual or unintended data that the system did not intend to disclose.

Because the component is part of the low-level boot and recovery path, exploitation typically requires a position that can invoke or influence fastboot operations. The precise trigger conditions, required privileges, and exact data that can be disclosed are not provided in the available summary; treat any public claims of exploit mechanics as unconfirmed until validated against the vendor advisory. The result is information disclosure rather than direct remote code execution, but the leaked material can aid subsequent attacks.

Am I affected? How to find it in your systems

Android Pixel devices are the only products named. These commonly appear as corporate-issued phones, developer test units, or personally owned devices enrolled in mobile-device-management (MDM) programs. Inventory every Pixel model under your control through MDM consoles, asset databases, or by querying device properties (manufacturer, model, build fingerprint) on the handset itself.

Check the installed firmware and security-patch level against the vendor advisory for this CVE; do not rely on generic Android version numbers alone. Configurations that leave fastboot unlocked or that routinely use unlock/flash workflows for imaging or testing increase exposure surface. Look for telemetry that records bootloader or fastboot state changes, unexpected unlock events, or anomalous access to recovery/fastboot modes. Because the flaw is information disclosure inside firmware, traditional application logs may not show clear indicators; prioritize device inventory and patch-level verification over hunting for post-exploitation artifacts that are not publicly documented.

How to remediate

Apply the vendor-supplied update that addresses CVE-2024-29745 as soon as it is available for the specific Pixel models in your environment. Follow the CISA-required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Confirm the exact patch identifier, build number, and installation method in the official advisory rather than assuming any particular release date or version string.

After patching, re-verify the security-patch level on each device and re-lock the bootloader where policy requires it. For the broader CWE-908 class, ensure that any custom recovery or imaging tooling you maintain also initializes resources correctly and does not reintroduce uninitialized-data paths. Document the update in your change-management system and retain evidence of successful application for audit purposes.

If you can't patch immediately

Until the vendor update can be deployed, reduce risk with compensating controls. Segment Pixel devices that must remain on unpatched firmware onto restricted network segments or guest Wi-Fi with limited access to corporate resources. Disable or tightly control physical and USB access that would allow an attacker to enter fastboot mode; enforce policies that keep the bootloader locked except during authorized maintenance windows.

Where MDM or enterprise mobility management is available, apply configuration profiles that restrict developer options, USB debugging, and unauthorized flashing. Increase monitoring for bootloader unlock events, unexpected reboots into recovery, or anomalous device check-ins. Virtual patching or network-level filtering is of limited value against a firmware-level information-disclosure issue, so focus on access control and rapid patching rather than signature-based detection. If mitigations cannot be applied and the device cannot be isolated, consider temporary removal from production use per the CISA guidance.

If your data may have been exposed

Actively exploited vulnerabilities can lead to data breaches even when the initial flaw is limited to information disclosure. If Pixel devices in your environment may have been targeted, treat any sensitive material that could have resided in uninitialized firmware buffers as potentially compromised and follow your incident-response playbook for credential rotation, session invalidation, and forensic review. Known ransomware use of this CVE is not documented. Separately, individuals can run a free exposure scan of their email address against known breach data sets to determine whether their credentials have appeared in prior public incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAndroid · Pixel
WeaknessCWE-908
Added to CISA KEVApr 4, 2024
Federal patch deadlineApr 25, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities