In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
ssvc
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Google
Google android |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: google_android
Published: 2024-03-11T16:35:22.043Z
Updated: 2025-03-27T15:16:09.506Z
Reserved: 2023-11-16T22:59:24.732Z
Link: CVE-2024-0047
Updated: 2024-08-01T17:41:15.915Z
Status : Modified
Published: 2024-03-11T17:15:45.620
Modified: 2025-03-27T16:15:20.623
Link: CVE-2024-0047
No data.