CVE-2024-0041
HIGHAndroid - Local Privilege Escalation via SystemStatusAnimationSchedulerImpl Race Condition
Title source: llmDescription
In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.
References (2)
Core 2
Core References
Mailing List, Patch
https://android.googlesource.com/platform/frameworks/base/+/d6f7188773409c8f5ad5fc7d3eea5b1751439e26
Patch, Vendor Advisory
https://source.android.com/security/bulletin/2024-02-01
Scores
CVSS v3
7.0
EPSS
0.0002
EPSS Percentile
6.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-362
Status
published
Products (1)
google/android
14.0
Published
Feb 16, 2024
Tracked Since
Feb 18, 2026