CVE-2024-0041
CVE-2024-0041
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.4EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
16 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Google · AndroidWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →