Lucene search

K
cvelistGoogle_androidCVELIST:CVE-2024-23713
HistoryMay 07, 2024 - 9:01 p.m.

CVE-2024-23713

2024-05-0721:01:29
google_android
www.cve.org
5
cve-2024-23713
input validation
notification settings
privilege escalation
local escalation

AI Score

7

Confidence

High

EPSS

0

Percentile

9.0%

In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CNA Affected

[
  {
    "vendor": "Google",
    "product": "Android",
    "versions": [
      {
        "version": "14",
        "status": "affected"
      },
      {
        "version": "13",
        "status": "affected"
      },
      {
        "version": "12L",
        "status": "affected"
      },
      {
        "version": "12",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

7

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVELIST:CVE-2024-23713