CVE-2024-31323
published 2024-07-09CVE-2024-31323: In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.10%
1.1th percentile
In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_healthfitness | >= 14-next:0 < 14-next:2024-06-01 | 14-next:2024-06-01 |
| platform | packages_modules_healthfitness | >= 14:0 < 14:2024-06-01 | 14:2024-06-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2024-31323: Android Security Bulletin 2024-06-01
CVE: CVE-2024-31323
Severity: HIGH
Type: EoP
Affected AOSP versions: 14
References: A-313425281
vendor_android·2024-06-01·CVSS 7.8
CVE-2024-31323 [HIGH] CVE-2024-31323: Android Security Bulletin 2024-06-01
CVE: CVE-2024-31323
Severity: HIGH
Type: EoP
Affected AOSP versions: 14
References: A-313425281
Android Security Bulletin 2024-06-01
CVE: CVE-2024-31323
Severity: HIGH
Type: EoP
Affected AOSP versions: 14
References: A-313425281
GHSA
GHSA-2cm2-8q39-h9qp: In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking
ghsa_unreviewed·2024-07-09
CVE-2024-31323 [HIGH] CWE-1021 GHSA-2cm2-8q39-h9qp: In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking
In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-31323: In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking
osv·2024-06-01
CVE-2024-31323 CVE-2024-31323: In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking
In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/packages/modules/HealthFitness/+/c4e13d15e8dd1df1bd827117d1a74c187ed2b3c2https://source.android.com/security/bulletin/2024-06-01https://android.googlesource.com/platform/packages/modules/HealthFitness/+/c4e13d15e8dd1df1bd827117d1a74c187ed2b3c2https://source.android.com/security/bulletin/2024-06-01
2024-07-09
Published