CVE-2024-11624

there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

History

24 Jul 2025, 15:15

Type Values Removed Values Added
First Time Google
Google android
CPE cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
References () https://source.android.com/security/bulletin/pixel/2024-12-01 - () https://source.android.com/security/bulletin/pixel/2024-12-01 - Vendor Advisory

03 Jan 2025, 23:15

Type Values Removed Values Added
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) Existe la posibilidad de agregar aplicaciones para omitir la VPN debido a permisos no declarados. Esto podría generar una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación.

03 Jan 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-03 04:15

Updated : 2025-07-24 15:15


NVD link : CVE-2024-11624

Mitre link : CVE-2024-11624

CVE.ORG link : CVE-2024-11624


JSON object : View

Products Affected

google

  • android
CWE
CWE-276

Incorrect Default Permissions