CVE-2024-31312

In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not needed for exploitation.
Configurations

No configuration.

History

21 Nov 2024, 09:13

Type Values Removed Values Added
References () https://android.googlesource.com/platform/frameworks/base/+/748055291460bcaafa3e53c7da1601a687959477 - () https://android.googlesource.com/platform/frameworks/base/+/748055291460bcaafa3e53c7da1601a687959477 -
References () https://source.android.com/security/bulletin/2024-06-01 - () https://source.android.com/security/bulletin/2024-06-01 -

31 Oct 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-276

11 Jul 2024, 13:06

Type Values Removed Values Added
Summary
  • (es) En varias ubicaciones, existe una posible fuga de información debido a la falta de una verificación de permiso. Esto podría llevar a la divulgación de información local exponiendo los medios reproducidos sin necesidad de privilegios de ejecución adicionales. La interacción del usuario no es necesaria para la explotación.

09 Jul 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 21:15

Updated : 2024-11-21 09:13


NVD link : CVE-2024-31312

Mitre link : CVE-2024-31312

CVE.ORG link : CVE-2024-31312


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions