CVE-2024-0015

In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

14 Mar 2025, 18:15

Type Values Removed Values Added
CWE CWE-280

16 Dec 2024, 14:39

Type Values Removed Values Added
First Time Google
Google android
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
References () https://android.googlesource.com/platform/frameworks/base/+/2ce1b7fd37273ea19fbbb6daeeaa6212357b9a70 - () https://android.googlesource.com/platform/frameworks/base/+/2ce1b7fd37273ea19fbbb6daeeaa6212357b9a70 - Mailing List, Patch
References () https://source.android.com/security/bulletin/2024-01-01 - () https://source.android.com/security/bulletin/2024-01-01 - Patch, Vendor Advisory

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://android.googlesource.com/platform/frameworks/base/+/2ce1b7fd37273ea19fbbb6daeeaa6212357b9a70 - () https://android.googlesource.com/platform/frameworks/base/+/2ce1b7fd37273ea19fbbb6daeeaa6212357b9a70 -
References () https://source.android.com/security/bulletin/2024-01-01 - () https://source.android.com/security/bulletin/2024-01-01 -

28 Aug 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

16 Feb 2024, 19:26

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-16 19:15

Updated : 2025-03-14 18:15


NVD link : CVE-2024-0015

Mitre link : CVE-2024-0015

CVE.ORG link : CVE-2024-0015


JSON object : View

Products Affected

google

  • android
CWE
NVD-CWE-noinfo CWE-280

Improper Handling of Insufficient Permissions or Privileges