First published: Mon Jan 06 2025(Updated: )
In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49748 is categorized as a critical vulnerability due to its potential for remote code execution.
To mitigate CVE-2024-49748, users should apply the latest security updates provided by Google for affected versions of Android.
CVE-2024-49748 is a heap buffer overflow vulnerability that can lead to out-of-bounds write.
No, exploitation of CVE-2024-49748 does not require any user interaction.
CVE-2024-49748 affects certain versions of Google Android.