CVE-2024-0019

In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*

History

26 Nov 2024, 15:17

Type Values Removed Values Added
CPE cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
References () https://android.googlesource.com/platform/frameworks/base/+/707fc94ec3df4cf6b985e6d06c2588690d1a025a - () https://android.googlesource.com/platform/frameworks/base/+/707fc94ec3df4cf6b985e6d06c2588690d1a025a - Patch
References () https://source.android.com/security/bulletin/2024-01-01 - () https://source.android.com/security/bulletin/2024-01-01 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.0
CWE NVD-CWE-noinfo
First Time Google android
Google

21 Nov 2024, 08:45

Type Values Removed Values Added
Summary
  • (es) En setListening de AppOpsControllerImpl.java, existe una forma posible de ocultar el indicador de privacidad del micrófono al reiniciar la UI del sistema debido a que falta una verificación de grabaciones activas. Esto podría provocar una denegación de servicio local sin necesidad de privilegios de ejecución adicionales. Se necesita la interacción del usuario para la explotación.
References () https://android.googlesource.com/platform/frameworks/base/+/707fc94ec3df4cf6b985e6d06c2588690d1a025a - () https://android.googlesource.com/platform/frameworks/base/+/707fc94ec3df4cf6b985e6d06c2588690d1a025a -
References () https://source.android.com/security/bulletin/2024-01-01 - () https://source.android.com/security/bulletin/2024-01-01 -

16 Feb 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-16 20:15

Updated : 2024-11-26 15:17


NVD link : CVE-2024-0019

Mitre link : CVE-2024-0019

CVE.ORG link : CVE-2024-0019


JSON object : View

Products Affected

google

  • android