First published: Tue Sep 03 2024(Updated: )
In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =14.0 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40659 has been classified as a local denial of service vulnerability affecting Android version 14.0.
To fix CVE-2024-40659, update your Android device to the latest version released by Google that addresses this vulnerability.
Exploiting CVE-2024-40659 can lead to a permanent disablement of the AndroidKeyStore key generation feature, causing local denial of service.
CVE-2024-40659 specifically affects Google Android version 14.0.
The primary mitigation for CVE-2024-40659 is to apply the official security update provided by Google for impacted devices.