CVE-2024-44096Initialization of a Resource with an Insecure Default in Google Android

Severity
4.4MEDIUMNVD
EPSS
0.0%
top 93.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 13

Description

there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages1 packages

CVEListV5google/androidAndroid kernel

🔴Vulnerability Details

2
GHSA
GHSA-3x4g-4374-v83h: there is a possible arbitrary read due to an insecure default value2024-09-13
OSV
CVE-2024-44096: there is a possible arbitrary read due to an insecure default value2024-09-01