Potential Escalation of Privileges Vulnerability in Google Settings App
CVE-2024-40652
What is CVE-2024-40652?
A vulnerability exists within the Android Settings application that allows unauthorized access during the device provisioning process. Specifically, in the onCreate method of the SettingsHomepageActivity.java, there is an oversight due to a missing permission check. This deficiency can enable local privilege escalation, potentially allowing attackers to access sensitive settings without requiring additional execution privileges. Although user interaction is necessary for exploitation, the implications of this vulnerability underline the importance of thorough permission validation in system applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Android 14
Android 13
Android 12L
References
CVSS V3.1
Timeline
Vulnerability published