CVE-2024-31323 Information
Jul 10, 2024
cve
Description
In onCreate of multiple files there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Reference
https://android.googlesource.com/platform/packages/modules/HealthFitness/+/c4e13d15e8dd1df1bd827117d1a74c187ed2b3c2 https://source.android.com/security/bulletin/2024-06-01
Share on: