Evidence used
- CISA confirms exploitation in the wild.
- EPSS is 0.67% for the current model date.
BlackTreeCVE IntelligenceAndroid · Pixel
CISA confirms exploitation in the wild and lists 2024-04-25 as the remediation due date.
CISA confirms exploitation in the wild and lists 2024-04-25 as the remediation due date.
Fix not verifiedAndroid Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.
Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
An attacker operating through local access may attempt exploitation without authentication after a user interaction. If successful, the issue may gain additional privileges.
Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
An attacker operating through local access may attempt exploitation without authentication after a user interaction. If successful, the issue may gain additional privileges.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2024-04-04.
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
CWE-280: Improper Handling of Insufficient Permissions or Privileges. The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Published 5 Apr 2024 · Last source change 21 Oct 2025, 23:05 UTC · CWE-280 · Improper Handling of Insufficient Permissions or Privileges
Core structured fields are present and their contributing authorities are shown above.