First published: Mon Jan 06 2025(Updated: )
In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =15.0 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49732 has a critical severity rating due to the potential for local escalation of privilege without user consent.
To address CVE-2024-49732, ensure that your Android system is updated to the latest security patch that mitigates this vulnerability.
Exploitation of CVE-2024-49732 could allow an attacker to gain unauthorized access to sensitive system functions without any user interaction.
CVE-2024-49732 impacts multiple versions of Android; users should refer to official security bulletins for specific version details.
No, CVE-2024-49732 can be exploited without any user interaction, increasing the risk of privilege escalation.