← Back

CVE-2024-0044

nvd nist
Published: Mar 11, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected (4)

Products: Google: Android
1 product
Android
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 12.0
Version 12.1
Version 13.0
Version 14.0

Timeline

No history available yet.