CVE-2024-0015

In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-16 19:15

Updated : 2025-03-14 18:15


NVD link : CVE-2024-0015

Mitre link : CVE-2024-0015

CVE.ORG link : CVE-2024-0015


JSON object : View

Products Affected

google

  • android
CWE
NVD-CWE-noinfo CWE-280

Improper Handling of Insufficient Permissions or Privileges