CVE-2024-32900: Google Android

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In lwis_fence_signal of lwis_debug.c, there is a possible Use after Free due to improper locking. This could lead to local escalation of privilege from hal_camera_default SELinux label with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected products

  • Google Android: affected versions not specified

Published 2024-06-13. Last modified 2026-06-17.