Logic Error in Accessibility Feature of Android Wear OS Products
CVE-2024-40664

6.2MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2024-40664?

A vulnerability has been identified in the setupAccessibilityServices function of AccessibilityFragment.java within Android Wear OS. This flaw involves a logic error that enables the possibility of hiding an active accessibility service. Exploitation of this vulnerability allows for a local denial of service, which can occur without the need for user interaction or elevated privileges, thereby increasing its potential impact on device usability.

Affected Version(s)

Android 14

Android 13

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.