CVE-2024-0015

In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

14 Mar 2025, 18:15

Type Values Removed Values Added
CWE CWE-280

16 Dec 2024, 14:39

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Google android
Google
CPE cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
References () https://android.googlesource.com/platform/frameworks/base/+/2ce1b7fd37273ea19fbbb6daeeaa6212357b9a70 - () https://android.googlesource.com/platform/frameworks/base/+/2ce1b7fd37273ea19fbbb6daeeaa6212357b9a70 - Mailing List, Patch
References () https://source.android.com/security/bulletin/2024-01-01 - () https://source.android.com/security/bulletin/2024-01-01 - Patch, Vendor Advisory

Information

Published : 2024-02-16 19:15

Updated : 2025-03-14 18:15


NVD link : CVE-2024-0015

Mitre link : CVE-2024-0015

CVE.ORG link : CVE-2024-0015


JSON object : View

Products Affected

google

  • android
CWE
NVD-CWE-noinfo CWE-280

Improper Handling of Insufficient Permissions or Privileges