PT-2024-30642 · Google · Android

Published

2024-12-01

·

Updated

2025-04-21

·

CVE-2024-43769

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A possible edge case in the isPackageDeviceAdmin function of PackageManagerService.java could prevent the uninstallation of CloudDpc due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

ASB-A-360807442
CVE-2024-43769

Affected Products

Android