In Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of null responses. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Aug 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-230 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2024-03-11T16:35:22.131Z
Updated: 2024-08-28T18:37:39.524Z
Reserved: 2023-11-16T22:59:25.319Z
Link: CVE-2024-0048
Vulnrichment
Updated: 2024-08-01T17:41:15.761Z
NVD
Status : Awaiting Analysis
Published: 2024-03-11T17:15:45.673
Modified: 2024-08-28T19:35:07.667
Link: CVE-2024-0048
Redhat
No data.