Medium 5.5
KEV-listed
CVE-2024-29745
In-the-wild exploitation of Google Pixel boot chain vulnerabilities
Vendor / product: Google Pixel
Event date: 2024-04-01
Public PoC: Yes
First tracked by RiskWire: 2026-08-19
CISA KEV catalog
Added to KEV
Federal remediation due
2024-04-25 (878 days overdue)
Ransomware campaign use
Unknown
CISA description
Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sources & citations (1)
- GrapheneOS Breaks Free From Pixels: Motorola Deal Promises Hardened Android on Flagships by 2027 webpronews.com · 2026-08-19
References
See CVE-2024-29745 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →