CVE Published: 11/03/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: google_android |
Vendor: Google |
Product: Android Status : PUBLISHED
CVE-2024-0044 Description
In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.