In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published: 2024-03-11T16:35:21.760Z

Updated: 2024-08-01T17:41:15.569Z

Reserved: 2023-11-16T22:59:22.652Z

Link: CVE-2024-0044

cve-icon Vulnrichment

Updated: 2024-08-01T17:41:15.569Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-11T17:15:45.450

Modified: 2024-07-03T01:44:34.730

Link: CVE-2024-0044

cve-icon Redhat

No data.