CVE-2024-49742: High severity Google Android vulnerability
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49742?
CVE-2024-49742 is classified as a high-severity vulnerability that allows local escalation of privilege.
How do I fix CVE-2024-49742?
To mitigate CVE-2024-49742, ensure that your application properly checks for notification access permissions before performing sensitive actions.
What software is affected by CVE-2024-49742?
CVE-2024-49742 affects devices running Google Android operating systems that utilize the NotificationAccessConfirmationActivity.java.
What type of vulnerability is CVE-2024-49742?
CVE-2024-49742 is a local escalation of privilege vulnerability caused by a missing permission check.
Is user interaction required for CVE-2024-49742 to be exploited?
Yes, user interaction is needed to exploit CVE-2024-49742.