Possible Local Escalation of Privilege Vulnerability in PackageInstallerService

CVE-2024-0044
Currently unrated 🤨

Key Information

Vendor
Google
Status
Android
Vendor
CVE Published:
11 March 2024

Badges

😄 Trended👾 Exploit Exists🔴 Public PoC📰 News Worthy

Summary

The vulnerability CVE-2024-0044 in the PackageInstallerService in Android 12 and 13 could potentially allow for local escalation of privilege without additional execution privileges needed. This vulnerability could be exploited with physical access to the device with enabled ADB debugging, allowing access to internal data of any user-installed app. The sensitive information contained within these apps could be exfiltrated and accessed by unauthorized parties. There is currently no known exploitation of this vulnerability by ransomware groups.

Affected Version(s)

Android = 14

Android = 13

Android = 12L

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Timeline

  • 👾

    Exploit exists.

  • Vulnerability started trending.

  • First article discovered by www.mobile-hacker.com

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database6 Proof of Concept(s)5 News Article(s)
.