CVE-2024-32896
published 2024-06-13CVE-2024-32896: there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges…
PriorityP181high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-07-04
Exploited in the wild
EPSS
3.01%
85.9th percentile
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | build_soong | >= 14-next:0 < 14-next:2024-06-05 | 14-next:2024-06-05 |
| platform | build_soong | >= 15-next:0 < 15-next:2024-09-01 | 15-next:2024-09-01 |
| platform | frameworks_base | >= 12:0 < 12:2024-09-01 | 12:2024-09-01 |
| platform | frameworks_base | >= 12L:0 < 12L:2024-09-01 | 12L:2024-09-01 |
| platform | frameworks_base | >= 13:0 < 13:2024-09-01 | 13:2024-09-01 |
| platform | frameworks_base | >= 14-next:0 < 14-next:2024-06-05 | 14-next:2024-06-05 |
| platform | frameworks_base | >= 14:0 < 14:2024-06-05 | 14:2024-06-05 |
| platform | frameworks_base | >= 14:0 < 14:2024-09-01 | 14:2024-09-01 |
| platform | frameworks_base | >= 15-next:0 < 15-next:2024-09-01 | 15-next:2024-09-01 |
| platform | hardware_interfaces | >= 14-next:0 < 14-next:2024-06-05 | 14-next:2024-06-05 |
| platform | hardware_interfaces | >= 15-next:0 < 15-next:2024-09-01 | 15-next:2024-09-01 |
| platform | system_sepolicy | >= 12:0 < 12:2024-09-01 | 12:2024-09-01 |
| platform | system_sepolicy | >= 12L:0 < 12L:2024-09-01 | 12L:2024-09-01 |
| platform | system_sepolicy | >= 13:0 < 13:2024-09-01 | 13:2024-09-01 |
| platform | system_sepolicy | >= 14-next:0 < 14-next:2024-06-05 | 14-next:2024-06-05 |
| platform | system_sepolicy | >= 14:0 < 14:2024-06-05 | 14:2024-06-05 |
| platform | system_sepolicy | >= 14:0 < 14:2024-09-01 | 14:2024-09-01 |
| platform | system_sepolicy | >= 15-next:0 < 15-next:2024-09-01 | 15-next:2024-09-01 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-32896 is an Elevation of Privilege (EoP) flaw in Android Pixel firmware exploited by forensic companies to unlock Android devices without a PIN and gain access to stored data; monitor for unauthorized privilege escalation on Android Pixel devices running AOSP versions 12, 12L, 13, and 14 ↗
- →CVE-2024-32896 requires user interaction for exploitation and involves a logic error leading to local privilege escalation; no additional execution privileges are needed by the attacker ↗
- →CVE-2024-32896 is tracked under Android internal reference A-324321147; use this reference to correlate patch status in Android security bulletins ↗
- →CVE-2024-32896 was also assigned CVE-2024-29748 by GrapheneOS, which discovered and reported the flaw; cross-reference both CVE identifiers when hunting for exploitation activity ↗
- →CISA flagged CVE-2024-32896 as a Known Exploited Vulnerability with a remediation due date of 2024-07-04; prioritize detection on Android Pixel devices that have not applied the 2024-06-01 Pixel security bulletin patch ↗
- ·Not all Android devices require the 2024-08-05 patch level fixes; device vendors may prioritize the initial patch level, which does not necessarily indicate increased exploitation risk ↗
- ·Google Pixel devices receive monthly security updates immediately, but other Android manufacturers may delay rollout for compatibility testing, leaving non-Pixel devices exposed longer ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-32896: In rebootRecoveryWithCommand of RecoverySystemService
osv·2024-09-01
CVE-2024-32896 CVE-2024-32896: In rebootRecoveryWithCommand of RecoverySystemService
In rebootRecoveryWithCommand of RecoverySystemService.java, there is a possible way to bypass a factory reset due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
GHSA
GHSA-qxgm-2hhj-rw7f: there is a possible way to bypass due to a logic error in the code
ghsa_unreviewed·2024-06-13
CVE-2024-32896 [HIGH] CWE-670 GHSA-qxgm-2hhj-rw7f: there is a possible way to bypass due to a logic error in the code
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
OSV
CVE-2024-32896: there is a possible way to bypass due to a logic error in the code
osv·2024-06-01
CVE-2024-32896 CVE-2024-32896: there is a possible way to bypass due to a logic error in the code
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
VulnCheck
Android Pixel Privilege Escalation Vulnerability
vulncheck·2024·CVSS 7.8
CVE-2024-32896 [HIGH] CWE-783 Android Pixel Privilege Escalation Vulnerability
Android Pixel Privilege Escalation Vulnerability
Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.
Affected: Android Pixel
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://source.android.com/docs/security/bulletin/pixel/2024-06-01; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://ti.qianxin.com/uploads/2024/08/19/2274f632f6a1d8acd2f1801c24887edb.pdf; https://source.android.com/docs/security/bulletin/2024-09-01; https://360.net/research/report/#:~:text=PDF-,Download,-Ransomware%20Prevalence%20
Android
CVE-2024-32896: Android Security Bulletin 2024-09-01
CVE: CVE-2024-32896
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14
References: A-324321147 [2]
vendor_android·2024-09-01·CVSS 7.8
CVE-2024-32896 [HIGH] CVE-2024-32896: Android Security Bulletin 2024-09-01
CVE: CVE-2024-32896
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14
References: A-324321147 [2]
Android Security Bulletin 2024-09-01
CVE: CVE-2024-32896
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14
References: A-324321147 [2]
CISA
Android Pixel Privilege Escalation Vulnerability
cisa·2024-06-13·CVSS 7.8
CVE-2024-32896 [HIGH] CWE-783 Android Pixel Privilege Escalation Vulnerability
Vulnerability: Android Pixel Privilege Escalation Vulnerability
Affected: Android Pixel
Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://source.android.com/docs/security/bulletin/pixel/2024-06-01; https://nvd.nist.gov/vuln/detail/CVE-2024-32896
Remediation Due Date: 2024-07-04
No detection rules found.
No public exploits indexed.
Checkpoint
9th September – Threat Intelligence Report
blogs_checkpoint·2024-09-09
CVE-2024-32896 9th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th September, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The German air traffic control agency, Deutsche Flugsicherung, has confirmed a cyberattack that impacted its administrative IT infrastructure. The extent of data accessed is still under investigation, and flight operations remained unaffected. No threat actor has claimed responsibility yet, though the attack is suspecte
Bleepingcomputer
Google fixes Android kernel zero-day exploited in targeted attacks
blogs_bleepingcomputer·2024-08-05·CVSS 7.8
CVE-2024-36971 [HIGH] Google fixes Android kernel zero-day exploited in targeted attacks
## Google fixes Android kernel zero-day exploited in targeted attacks
## Sergiu Gatlan
Android security updates this month patch 46 vulnerabilities, including a high-severity remote code execution (RCE) exploited in targeted attacks.
The zero-day, tracked as CVE-2024-36971 , is a use after free (UAF) weakness in the Linux kernel's network route management. It requires System execution privileges for successful exploitation and allows altering the behavior of certain network connections.
Google says that "there are indications that CVE-2024-36971 may be under limited, targeted exploitation," with threat actors likely exploiting to gain arbitrary code execution without user interaction on unpatched devices.
Clément Lecigne, a security researcher from Google's Threat Analysis Group (TAG)
2024-06-13
Published
2024-06-13
Added to CISA KEV
Exploited in the wild