CVE-2024-43080
HIGHAndroid - Local Privilege Escalation via Unsafe Deserialization in AppRestrictionsFragment
Title source: llmDescription
In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
References (2)
Core 2
Core References
Mailing List, Patch
https://android.googlesource.com/platform/packages/apps/Settings/+/26ce013dfd7e59a451acc66e7f05564e0884d46b
Patch, Vendor Advisory
https://source.android.com/security/bulletin/2024-11-01
Scores
CVSS v3
7.8
EPSS
0.0009
EPSS Percentile
25.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (5)
google/android
12.0
google/android
12.1
google/android
13.0
google/android
14.0
google/android
15.0
Published
Nov 13, 2024
Tracked Since
Feb 18, 2026