CVE-2024-31316Frameworks Base vulnerability

4 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 83.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9

Description

In onResult of AccountManagerService.java, there is a possible way to perform an arbitrary background activity launch due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

Androidplatform/frameworks_base14-next:014-next:2024-06-01+4
CVEListV5google/android4 versions+3
NVDgoogle/android4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-88wv-r6ff-qxwp: In onResult of AccountManagerService2024-07-09
OSV
CVE-2024-31316: In onResult of AccountManagerService2024-06-01

📋Vendor Advisories

1
Android
CVE-2024-31316: Android Security Bulletin 2024-06-01 CVE: CVE-2024-31316 Severity: HIGH Type: EoP Affected AOSP versions: 12, 12L, 13, 14 References: A-3219412322024-06-01