Possible Out of Bounds Write in attp_build_value_cmd Could Lead to Remote Code Execution

CVE-2024-0039
Currently unrated 🤨

Key Information

Vendor
Google
Status
Android
Vendor
CVE Published:
11 March 2024

Badges

👾 Exploit Exists🔴 Public PoC📰 News Worthy

Summary

In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Version(s)

Android = 14

Android = 13

Android = 12L

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Timeline

  • 👾

    Exploit exists.

  • Vulnerability published.

  • First article discovered by securityonline.info

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database1 Proof of Concept(s)1 News Article(s)
.