In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe deserialization. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-07-09 21:15
Updated : 2024-07-11 15:05
NVD link : CVE-2024-31317
Mitre link : CVE-2024-31317
CVE.ORG link : CVE-2024-31317
JSON object : View
Products Affected
No product.
CWE
CWE-502
Deserialization of Untrusted Data