Logic Error in Accessibility Feature of Android Wear OS Products
CVE-2024-40664
Currently unrated
What is CVE-2024-40664?
A vulnerability has been identified in the setupAccessibilityServices function of AccessibilityFragment.java within Android Wear OS. This flaw involves a logic error that enables the possibility of hiding an active accessibility service. Exploitation of this vulnerability allows for a local denial of service, which can occur without the need for user interaction or elevated privileges, thereby increasing its potential impact on device usability.
Affected Version(s)
Android 14
Android 13