PT-2024-2065 · Google · Android

Published

2024-02-01

·

Updated

2024-12-16

·

CVE-2024-0035

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The issue exists due to insufficient input validation in the onNullBinding function of TileLifecycleManager.java. This could allow an attacker to launch an activity from the background, leading to local escalation of privilege without needing additional execution privileges. User interaction is not required for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

RCE

Weakness Enumeration

Related Identifiers

ASB-A-300903792
BDU:2024-01957
CVE-2024-0035

Affected Products

Android