PT-2024-33083 · Unknown · Magisk App
Vvb2060
·
Published
2024-11-04
·
Updated
2024-11-05
·
CVE-2024-48336
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Magisk App versions prior to 27007
Description
The issue arises from the
install() function in ProviderInstaller.java, which fails to verify the GMS app before loading it. This oversight allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app, thereby escalating privileges to root via a crafted package. Notably, user interaction is not required for exploitation.Recommendations
For Magisk App versions prior to 27007, as a temporary workaround, consider disabling the
install() function until a patch is available. Restrict access to the ProviderInstaller.java module to minimize the risk of exploitation. Avoid using crafted packages that could exploit this issue until the Magisk App is updated to version 27007 or later.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magisk App