PT-2025-1035 · Google · Android

Published

2025-01-01

·

Updated

2025-01-22

·

CVE-2024-49747

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The issue is related to a logic error in the code of gatt sr.cc, specifically in the gatts process read by type req function, which could lead to an out-of-bounds write. This might result in remote code execution without requiring additional execution privileges. User interaction is not necessary for exploitation. The vulnerability is associated with incorrect code generation management in the Android operating system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Memory Corruption

Code Injection

Weakness Enumeration

Related Identifiers

ASB-A-364027038
BDU:2025-00240
CVE-2024-49747

Affected Products

Android