First published: Mon Feb 05 2024(Updated: )
In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =14.0 |
https://android.googlesource.com/platform/frameworks/base/+/d6f7188773409c8f5ad5fc7d3eea5b1751439e26
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0041 has a medium severity rating due to its potential for local escalation of privilege.
To fix CVE-2024-0041, ensure that you update your Android device to the latest security patch provided by Google.
CVE-2024-0041 affects Google Android version 14.0 and potentially earlier versions.
CVE-2024-0041 does not require user interaction to exploit, making it a higher risk.
CVE-2024-0041 is categorized as a race condition vulnerability that can lead to privilege escalation.