CVE-2024-0041 — Race Condition in Frameworks Base
Severity
7.0HIGHNVD
EPSS
0.0%
top 94.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 16
Description
In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9
Affected Packages4 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Android▶
CVE-2024-0041: Android Security Bulletin 2024-02-01
CVE: CVE-2024-0041
Severity: HIGH
Type: EoP
Affected AOSP versions: 14
References: A-300741186↗2024-02-01