Possible FRP Bypass in WiFi Edit Content
CVE-2024-40650

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
11 September 2024

What is CVE-2024-40650?

A vulnerability exists in the Settings app of Android, specifically in the wifi_item_edit_content section of styles.xml. This issue is characterized by a potential factory reset protection (FRP) bypass, stemming from the absence of an adequate check for the FRP state. As a consequence, it may enable unauthorized local escalation of privileges without necessitating any additional execution rights or user input for exploitation. This vulnerability poses security risks that could allow unauthorized access to device capabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Android 14

Android 13

Android 12L

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.