First published: Mon Nov 04 2024(Updated: )
In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =12.0 | |
Android | =12.1 | |
Android | =13.0 | |
Android | =14.0 | |
Android | =15.0 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43087 has been classified as a local escalation of privilege vulnerability.
To mitigate CVE-2024-43087, update your Android device to a version that includes the relevant security patches.
CVE-2024-43087 affects Android versions 12.0, 12.1, 13.0, 14.0, and 15.0.
CVE-2024-43087 is caused by a logic error in the getInstalledAccessibilityPreferences function of AccessibilitySettings.java.
CVE-2024-43087 requires local access to the device, making it a local privilege escalation vulnerability.