PT-2024-20022 · Google · Android 14
Published
2024-05-01
·
Updated
2024-12-17
·
CVE-2024-23706
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android 14
Description
The issue is related to an improper input validation that could lead to a bypass of health data permissions. This could result in a local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations
For Android 14, apply the security updates released by Google to patch the critical bug.
As a temporary workaround, consider restricting access to health data permissions until the issue is resolved.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android 14