CVE-2024-31316

In onResult of AccountManagerService.java, there is a possible way to perform an arbitrary background activity launch due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*

History

17 Dec 2024, 17:21

Type Values Removed Values Added
First Time Google android
Google
References () https://android.googlesource.com/platform/frameworks/base/+/3457d82f8e265ad615b38f6a2aa3c33f1e100cb9 - () https://android.googlesource.com/platform/frameworks/base/+/3457d82f8e265ad615b38f6a2aa3c33f1e100cb9 - Mailing List, Patch
References () https://source.android.com/security/bulletin/2024-06-01 - () https://source.android.com/security/bulletin/2024-06-01 - Patch, Vendor Advisory
CPE cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

Information

Published : 2024-07-09 21:15

Updated : 2024-12-17 17:21


NVD link : CVE-2024-31316

Mitre link : CVE-2024-31316

CVE.ORG link : CVE-2024-31316


JSON object : View

Products Affected

google

  • android