CVE-2024-40662
HIGHAndroid - Local Privilege Escalation via Malformed Uri Object
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-40662. PoCs published by bb33bb.
AI-analyzed exploit summary The repository contains only legitimate Android framework source files (e.g., BaseDhcpStateMachine.java, CaptivePortal.java) without any exploit code or technical analysis. No PoC or vulnerability details are present.
Description
In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Exploits (1)
The repository contains only legitimate Android framework source files (e.g., BaseDhcpStateMachine.java, CaptivePortal.java) without any exploit code or technical analysis. No PoC or vulnerability details are present.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H