PT-2025-1033 · Google · Android

Published

2025-01-01

·

Updated

2025-01-22

·

CVE-2024-49724

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The issue is related to a race condition in multiple functions of AccountManagerService.java, which could allow an attacker to bypass permissions and launch protected activities. This could lead to a local escalation of privilege with no additional execution privileges needed. User interaction is required for exploitation. The vulnerability is also related to a buffer copy without checking the size of the input data in the Android operating system's Framework component, which could allow an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Default Permissions

Race Condition

Buffer Overflow

Weakness Enumeration

Related Identifiers

ASB-A-369351375
BDU:2025-00238
CVE-2024-49724

Affected Products

Android