CVE-2024-0044

MEDIUM

PackageInstallerService - Privilege Escalation

Title source: llm

Description

In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploits (17)

nomisec WORKING POC 330 stars
by 0xbinder · poc
https://github.com/0xbinder/CVE-2024-0044
nomisec WORKING POC 170 stars
by canyie · poc
https://github.com/canyie/CVE-2024-0044
nomisec SUSPICIOUS 76 stars
by scs-labrat · poc
https://github.com/scs-labrat/android_autorooter
nomisec WORKING POC 24 stars
by sridhar-sec · poc
https://github.com/sridhar-sec/EvilDroid
nomisec WORKING POC 13 stars
by Re13orn · poc
https://github.com/Re13orn/CVE-2024-0044-EXP
nomisec WORKING POC 12 stars
by MrW0l05zyn · poc
https://github.com/MrW0l05zyn/cve-2024-0044
nomisec WORKING POC 5 stars
by Athexblackhat · poc
https://github.com/Athexblackhat/EXPLOITER
nomisec WORKING POC 5 stars
by l1ackerronin · poc
https://github.com/l1ackerronin/CVE-2024-0044
nomisec WORKING POC 4 stars
by Athexhacker · poc
https://github.com/Athexhacker/EXPLOITER
nomisec WORKING POC 4 stars
by 007CRIPTOGRAFIA · poc
https://github.com/007CRIPTOGRAFIA/c-CVE-2024-0044
nomisec WORKING POC 2 stars
by Dit-Developers · poc
https://github.com/Dit-Developers/CVE-2024-0044
nomisec WORKING POC 1 stars
by hunter24x24 · poc
https://github.com/hunter24x24/cve_2024_0044
gitlab STUB
by user.gameover.user · poc
https://gitlab.com/user.gameover.user/testtt
nomisec WORKING POC
by JackTekno · poc
https://github.com/JackTekno/Chrome-Forensic_CVE-2024-0044
nomisec NO CODE
by HoyoenKim · poc
https://github.com/HoyoenKim/CVE-2024-0044_PoC
github WORKING POC
by GabrieleDattile · pythonpoc
https://github.com/GabrieleDattile/cve-pocs/tree/main/CVE/CVE-2024-0044
nomisec WORKING POC
by Kai2er · poc
https://github.com/Kai2er/CVE-2024-0044-EXP

Scores

CVSS v3 6.7
EPSS 0.0916
EPSS Percentile 92.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74 CWE-75
Status published
Products (4)
google/android 12.0
google/android 12.1
google/android 13.0
google/android 14.0
Published Mar 11, 2024
Tracked Since Feb 18, 2026