NA - CVE-2024-43080 - In onReceive of AppRestrictionsFragment.java,...
In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional...
NA - CVE-2024-43081 - In installExistingPackageAsUser of...
In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with...
In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution...
NA - CVE-2024-43083 - In validate of WifiConfigurationUtil.java ,...
In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution...
NA - CVE-2024-43084 - In visitUris of multiple files, there is a...
In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed....
NA - CVE-2024-43085 - In handleMessage of UsbDeviceManager.java,...
In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic error in the code. This could lead to local...
NA - CVE-2024-43086 - In validateAccountsInternal of...
In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused deputy. This could lead to local information...
NA - CVE-2024-43087 - In getInstalledAccessibilityPreferences of...
In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in...
NA - CVE-2024-43088 - In multiple functions in AppInfoBase.java,...
In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due to a missing permission check. This could lead...
NA - CVE-2024-43089 - In updateInternal of MediaProvider.java , there...
In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to local escalation of privilege with no...