PT-2024-26149 · Google · Android

Published

2024-08-15

·

Updated

2025-09-29

·

CVE-2024-34739

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A logic error in the code of shouldRestrictOverlayActivities in UsbProfileGroupSettingsManager.java could lead to a possible escape from SUW, resulting in local escalation of privilege with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

ASB-A-294105066
CVE-2024-34739

Affected Products

Android