First published: Wed Sep 04 2024(Updated: )
Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Android | =12.0 | |
Samsung Android | =12.0-smr_sep-2024-r1 | |
Samsung Android | =13.0 | |
Samsung Android | =13.0-smr-jun-2024-r1 | |
Samsung Android | =14.0 | |
Samsung Android | =14.0-smr-jun-2024-r1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34637 has been classified with a high severity due to its potential to allow local attackers to bypass important security restrictions.
To fix CVE-2024-34637, ensure that your Samsung Android device is updated to SMR Sep-2024 Release 1 for Android 12 or SMR Jun-2024 Release 1 for Android 13 and 14.
CVE-2024-34637 affects Samsung Android versions 12, 13, and 14 prior to their respective security release updates.
CVE-2024-34637 cannot be exploited remotely as it requires local access to the device.
CVE-2024-34637 is categorized as an improper access control vulnerability in the WindowManagerService.