CVE-2024-40662 Information
Sep 12, 2024
cve
Description
In scheme of Uri.java there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Reference
https://android.googlesource.com/platform/frameworks/base/+/e7af00cafb52a25933ec4edb80c5111d42af0237 https://source.android.com/security/bulletin/2024-09-01
Share on: