CERT-In Vulnerability Note
CIVN-2024-0191
Multiple Vulnerabilities in Google Devices
Original Issue Date:June 18, 2024
Severity Rating: HIGH
Software Affected
- Google Pixel Firmware in devices, such as Pixel 5a with 5G, Pixel 6a, Pixel 6, Pixel 6 Pro, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel 8, Pixel 8 Pro, Pixel 8a, and Pixel Fold.
Overview
Multiple vulnerabilities have been reported in Google devices, which could be exploited by a remote attacker to gain access to sensitive information, perform a denial of service (DoS) attack, execute arbitrary code, escalate privileges, and potentially result in complete compromise of the vulnerable system.
Description
These vulnerabilities exist due to improper input validation flaws within the Exynos RIL, Modem, LWIS, ACPM, Fingerprint Sensor, Telephony, Audio, WLAN HOST, Trusty OS, Pixel Firmware, LDFW, Trusty/TEE, Goodix, Mali, avcp, confirmationui, CPIF, v4l2, and GsmSs subcomponents in Pixel devices. A remote attacker could exploit these vulnerabilities by sending specially crafted requests to the targeted system.
Successful exploitation of these vulnerabilities could allow a remote attacker to gain access to sensitive information, perform a denial of service (DoS) attack, execute arbitrary code, escalate privileges, and potentially result in the complete compromise of the vulnerable system.
Note: CVE-2024-32896 (elevation of privilege) is being exploited in the wild.
Solution
Apply appropriate updates as mentioned in Google advisory:
https://source.android.com/docs/security/bulletin/pixel/2024-06-01
Vendor Information
Google
https://source.android.com/docs/security/bulletin/pixel/2024-06-01
References
Bleeping Computer
https://www.bleepingcomputer.com/news/security/google-patches-exploited-android-zero-day-on-pixel-devices/
CVE Name
CVE-2024-32896
CVE-2024-32897
CVE-2023-50803
CVE-2024-32902
CVE-2024-32923
CVE-2024-29784
CVE-2024-29787
CVE-2024-32900
CVE-2024-32903
CVE-2024-32919
CVE-2024-32921
CVE-2024-29778
CVE-2024-32898
CVE-2024-32920
CVE-2024-32904
CVE-2024-32915
CVE-2024-32926
CVE-2024-32912
CVE-2024-32924
CVE-2023-43537
CVE-2023-43543
CVE-2023-43544
CVE-2023-43545
CVE-2023-43555
CVE-2024-32930
CVE-2024-32918
CVE-2024-32896
CVE-2024-32925
CVE-2024-32891
CVE-2024-32892
CVE-2024-32899
CVE-2024-32906
CVE-2024-32908
CVE-2024-32909
CVE-2024-32922
CVE-2024-29786
CVE-2024-32905
CVE-2024-32913
CVE-2024-32895
CVE-2024-32916
CVE-2024-32901
CVE-2024-32907
CVE-2024-32911
CVE-2024-32917
CVE-2024-29780
CVE-2024-29781
CVE-2024-29785
CVE-2024-32893
CVE-2024-32894
CVE-2024-32910
CVE-2024-32914
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|