CVE-2024-0044

Published Mar 11, 2024

Last updated a year ago

CVSS medium 6.7
Mobile device

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-0044 is a privilege escalation vulnerability found in the Android operating system, specifically within the `createSessionInternal` method of `PackageInstallerService.java`. The flaw stems from improper input validation, which allows an attacker to bypass security checks and execute code in the context of nearly any non-system application. This "run-as any app" capability can lead to local escalation of privilege without requiring any user interaction for exploitation. The vulnerability affects Android versions 12, 12.1, and 13. It was addressed by Google in the March 2024 Android Security Bulletin, with a fix implemented in Android 14. The issue was discovered and reported to Google by Meta Red Team X.

Description
In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Source
security@android.com
NVD status
Modified
Products
android

Risk scores

CVSS 3.1

Type
Primary
Base score
6.7
Impact score
5.9
Exploitability score
0.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
MEDIUM

Weaknesses

nvd@nist.gov
CWE-74
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-75

Social media

Hype score
Not currently trending

Configurations