CVE-2024-0015
HIGHGoogle Android Intent Redirection - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-0015. PoCs published by UmVfX1BvaW50.
AI-analyzed exploit summary The repository contains minimal Android app code (MainActivity and DreamService) with no functional exploit logic. The README mentions a PoC but lacks technical details or actual exploit implementation.
Description
In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Exploits (1)
The repository contains minimal Android app code (MainActivity and DreamService) with no functional exploit logic. The README mentions a PoC but lacks technical details or actual exploit implementation.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H