CVE-2024-31320 Information
Jul 10, 2024
cve
Description
In setSkipPrompt of AssociationRequest.java there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Reference
https://android.googlesource.com/platform/frameworks/base/+/9722ce9d733edab76163fbcd21b231424e3d7061 https://android.googlesource.com/platform/frameworks/base/+/df49e0e3083b0707e2cca5a5956b49f14ded078e https://source.android.com/security/bulletin/2024-07-01
Share on: