CVE-2024-29748

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 7 articles

EPSS Score

Source: FIRST.org · 2026-05-24
0.41%
probability
This CVE has a 0.41% probability of being exploited in the next 30 days.
0% Top 61.7th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
API factory reset can be interrupted with physical access

Google Project Zero

Patched
April 2, 2024
Reported by
???
Root Cause Analysis
???

Signal Intelligence

Confidence
92%
EPSS 0.41%
Mentions 7
Last Seen Feb 28, 2025

CNA Information

Analyst Note

CVE-2024-29748 demonstrates confirmed exploitation in real-world attacks against Pixel devices by forensics firms and law enforcement, with coverage from multiple reputable security sources and validation by Google's project zero team. The HIGH CVSS score (7.8), local privilege escalation capability, and documented active exploitation strongly support the CONFIRMED status despite absence from CISA KEV.

Threat Actors 3

RomCom
apt_group Financial gain 🇷🇺 RU
Void Rabisu
apt_group Financial gain 🇷🇺 RU
Red Dev 17
apt_group 🇨🇳 CN

Triage Info

Decided atMar 03, 2026