PT-2024-15298 · Google · Android

Published

2024-01-01

·

Updated

2024-12-16

·

CVE-2024-0021

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to the fixed version
Description The issue is related to a logic error in the code of NotificationAccessConfirmationActivity.java, which could allow an app in the work profile to enable notification listener services. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations For Android versions prior to the fixed version, as a temporary workaround, consider disabling the NotificationAccessConfirmationActivity until a patch is available. Restrict access to the notification listener services to minimize the risk of exploitation. Avoid using the NotificationAccessConfirmationActivity in the work profile until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

ASB-A-282934003
CVE-2024-0021

Affected Products

Android