CVE-2024-34740 Information

Description

In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Reference

https://android.googlesource.com/platform/frameworks/libs/modules-utils/+/700c28908051ceb55e1456d2d21229bc17c6895a https://android.googlesource.com/platform/frameworks/base/+/e8b6505647be558ed3a167a1e13c53dfc227d22b https://source.android.com/security/bulletin/2024-08-01

Share on: