CVE-2024-34740 Information
Aug 17, 2024
cve
Description
In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Reference
https://android.googlesource.com/platform/frameworks/libs/modules-utils/+/700c28908051ceb55e1456d2d21229bc17c6895a https://android.googlesource.com/platform/frameworks/base/+/e8b6505647be558ed3a167a1e13c53dfc227d22b https://source.android.com/security/bulletin/2024-08-01
Share on: