Infinite Loop Vulnerability in Intent.java of Android Framework
CVE-2024-40675
7.5HIGH
Key Information:
What is CVE-2024-40675?
A vulnerability exists in the parseUriInternal function of the Intent.java component of the Android framework. This flaw arises from insufficient input validation, potentially leading to an infinite loop. Exploitation of this vulnerability could result in a local denial of service situation, allowing an attacker to disrupt device functionality without needing any additional execution privileges. Importantly, user interaction is not required for the exploitation of this weakness.
Affected Version(s)
Android 14
Android 13
Android 12L