Out of Bounds Write in GATT Service Implementation of Android
CVE-2024-43770

8.8HIGH

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
21 January 2025

Summary

A vulnerability exists in the GATT service implementation of the Android operating system that could allow an out of bounds write due to a lack of proper boundaries checks within the gatts_process_find_info function. This weakness may enable an attacker to execute arbitrary code remotely without requiring additional privileges or user interaction. Addressing this issue is critical for maintaining the integrity and security of Android devices.

Affected Version(s)

Android 15

Android 14

Android 13

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.