Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bishoy Gendy

Researcher fromGoogle
#32218of 53,633
7.8Total CVSS
Vulnerabilities · 1
PT-2024-26137
7.8
2024-07-01
Google · Android · CVE-2024-34723
**Name of the Vulnerable Software and Affected Versions** Android versions (affected versions not specified) **Description** The issue is related to a logic error in the code of ParcelableListBinder.java, specifically in the onTransact method. This error could allow an attacker to steal the `mAllowlistToken`, enabling them to launch an app from the background, which could lead to local escalation of privilege. No additional execution privileges are needed, and user interaction is not required for exploitation. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.