In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-502 | |
Metrics |
ssvc
|
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* | |
Vendors & Products |
Google
Google android |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2025-03-27T15:16:09.506Z
Reserved: 2023-11-16T22:59:24.732Z
Link: CVE-2024-0047

Updated: 2024-08-01T17:41:15.915Z

Status : Modified
Published: 2024-03-11T17:15:45.620
Modified: 2025-03-27T16:15:20.623
Link: CVE-2024-0047

No data.