icon

We found results for “

CVE-2024-34734

Good to know:

icon

Date: August 15, 2024

In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Language: KOTLIN

Severity Score

Severity Score

Weakness Type (CWE)

Insecure Default Initialization of Resource

CWE-1188

Insecure Default Variable Initialization

CWE-453

Top Fix

icon

Upgrade Version

Upgrade to version android-14.0.0_r55

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us