CVE-2024-31322

July 9, 2024, 9:15 p.m.

Product(s) Impacted

Android

Description

In updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Setting while retaining Accessibility Service due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Weaknesses

Date

Published: July 9, 2024, 9:15 p.m.

Last Modified: July 9, 2024, 9:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

security@android.com

References