Skip to main content

CVE-2024-29748

7.8
HIGHCVSS v3.1 Base Score
0.41%
LOW RiskEPSS (62nd percentile)
KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Published: 4/5/2024
Modified: 10/24/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Android Pixel Privilege Escalation Vulnerability

Vendor / Product:

Android Pixel

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due Date: 4/25/2024(OVERDUE)
Added to KEV:

4/4/2024

Notes:

https://source.android.com/docs/security/bulletin/pixel/2024-04-01; https://nvd.nist.gov/vuln/detail/CVE-2024-29748

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.41%LOW Exploitation Risk
62nd percentile

This vulnerability has a 0.41% probability of being exploited in the next 30 days, ranking higher than 62% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-755)

CVE-2025-10156CRITICAL 9.8

An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This is achieved by crafting a ZIP archive containing a file with a bad Cyclic Redundancy Check (CRC), which causes the scanner to halt and fail to analyze the contents for malicious pickle files. When the file incorrectly considered safe is loaded, it can lead to the execution of malicious code.

9/17/2025
CVE-2023-6267HIGH 8.6

A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security.

1/25/2024
CVE-2021-42142CRITICAL 9.8

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vulnerability allows remote attackers to cause a denial of service and false-positive packet drops.

1/23/2024
CVE-2021-42141CRITICAL 9.8

An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with different epoch numbers in the packets Client_Hello, Client_key_exchange, and Change_cipher_spec, which may cause denial of service.

1/22/2024
CVE-2023-38406CRITICAL 9.8

bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."

11/6/2023

Similar SeverityHIGH