CVE-2024-27222: High severity android vulnerability
In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANTURIPERMISSIONS Attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27222?
The severity of CVE-2024-27222 is rated as high due to the potential for local escalation of privilege.
How do I fix CVE-2024-27222?
To fix CVE-2024-27222, users should update their Android device to the latest security patch provided by Google.
What causes CVE-2024-27222?
CVE-2024-27222 is caused by an Intent Redirect vulnerability within the FaceEnrollFoldPage.java that permits unauthorized file access.
Is user interaction required to exploit CVE-2024-27222?
No, user interaction is not required to exploit CVE-2024-27222, making it a more critical issue.
Which versions of Android are affected by CVE-2024-27222?
CVE-2024-27222 specifically affects Android version 13.0.