CVE-2024-0030: Medium severity android vulnerability
Published Feb 5, 2024
·Updated
In btiftobtaresponse of btifgattutil.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
6 affected components
Google Android
Google Android=11.0
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android=14.0
Remediation
Patch Available
Event History
Feb 5, 2024
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Feb 16, 2024
CVE Published
via MITRE·12:08 AM
Data Sourced
via MITRE·12:08 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0030?
CVE-2024-0030 has been classified as a medium severity vulnerability.
2
How does CVE-2024-0030 affect Android devices?
CVE-2024-0030 can lead to local information disclosure due to an out of bounds read without requiring user interaction.
3
Which versions of Android are affected by CVE-2024-0030?
CVE-2024-0030 affects Google Android versions 11.0, 12.0, 12.1, 13.0, and 14.0.
4
Is user interaction needed for exploiting CVE-2024-0030?
No, user interaction is not needed for the exploitation of CVE-2024-0030.
5
How do I fix CVE-2024-0030?
To fix CVE-2024-0030, users should ensure their Android device is updated to the latest security patches provided by Google.