The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 04 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Magisk
Magisk magisk
Weaknesses CWE-829
CPEs cpe:2.3:a:magisk:magisk:*:*:*:*:*:*:*:*
Vendors & Products Magisk
Magisk magisk
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 04 Nov 2024 17:45:00 +0000

Type Values Removed Values Added
Description The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-04T20:06:56.981Z

Reserved: 2024-10-08T00:00:00

Link: CVE-2024-48336

cve-icon Vulnrichment

Updated: 2024-11-04T19:26:52.273Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-04T18:15:05.027

Modified: 2024-11-04T20:35:10.193

Link: CVE-2024-48336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.