PT-2024-26147 · Unknown · Activityclientcontroller.Java

Published

2024-08-01

·

Updated

2024-12-17

·

CVE-2024-34737

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ActivityClientController.java (affected versions not specified)
Description The issue is related to a logic error in the ensureSetPipAspectRatioQuotaTracker function of ActivityClientController.java. This error can lead to the generation of unmovable and undeletable picture-in-picture (pip) windows. As a result, it could allow for local escalation of privilege without requiring additional execution privileges. Notably, user interaction is not necessary for the exploitation of this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ASB-A-283103220
CVE-2024-34737

Affected Products

Activityclientcontroller.Java