Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-0022

May 7, 2024, 9:15 p.m.

Product(s) Impacted

Android

  • UNKNOWN

Description

In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Weaknesses

Date

Published: May 7, 2024, 9:15 p.m.

Last Modified: May 7, 2024, 9:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

security@android.com

References