CVE-2024-43080

HIGH

Android - Privilege Escalation

Title source: llm

Description

In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 25.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (5)

google/android
google/android
google/android
google/android
google/android

Timeline

Published Nov 13, 2024
Tracked Since Feb 18, 2026