Vulnerability record · CVE-2024-29745 · published 5 April 2024
CVE-2024-29745: Android Pixel firmware uninitialized data information disclosure
Google · Android
CVE-2024-29745 is an information disclosure flaw in Android on Pixel devices caused by use of uninitialized data (CWE-908). A local attacker can read data that should not be exposed, and no user interaction is required. It matters because it leaks potentially sensitive memory contents on affected devices.
Description
there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityIt is listed in CISA KEV with known exploitation, though the CVSS score is medium and EPSS is low.
What it is
CVE-2024-29745 is an information disclosure flaw in Android on Pixel devices caused by use of uninitialized data (CWE-908). A local attacker can read data that should not be exposed, and no user interaction is required. It matters because it leaks potentially sensitive memory contents on affected devices.
Impact
An attacker with local access gains disclosure of uninitialized memory contents, which may include sensitive data. There is no integrity or availability impact.
Attack surface
The vulnerability is local (AV:L) and requires low privileges (PR:L) with no user interaction (UI:N). It is reached by a local process or app running on the device, not over the network.
Exploitation
CISA added it to the Known Exploited Vulnerabilities catalog on 2024-04-04, indicating known exploitation, while EPSS is low at 0.00482 (40th percentile). No ransomware campaign use is documented.
What to do
- Apply the April 2024 Android Pixel security bulletin update from Google.
- If patching is not possible, follow CISA guidance to discontinue use of affected devices.
- Restrict installation of untrusted local apps and limit local access to devices.
- Monitor for and remove any unapproved local applications or processes.
- Track vendor advisories for updated Pixel firmware builds.
Detection
- Monitor for anomalous local processes or apps attempting to read memory or system resources.
- Review device logs for unexpected information disclosure or access to uninitialized data paths.
- Use mobile threat defense tooling to flag suspicious local app behavior on Pixel devices.
- Audit installed applications and permissions for unnecessary local access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-29745 to the Known Exploited Vulnerabilities catalog on 4 April 2024 as "Android Pixel Information Disclosure Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 25 April 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://source.android.com/security/bulletin/pixel/2024-04-01 | Vendor Advisory |
| https://source.android.com/security/bulletin/pixel/2024-04-01 | Vendor Advisory |
| https://twitter.com/GrapheneOS/status/1775306481622995226 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-29745 | US Government Resource |
Track CVE-2024-29745 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-29745), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.