Metrics
Affected Vendors & Products
Link | Providers |
---|---|
https://source.android.com/security/bulletin/2025-01-01 |
![]() ![]() |
Tue, 18 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-276 | |
Metrics |
cvssV3_1
|
Tue, 18 Feb 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-502 | |
Metrics |
cvssV3_1
|
Wed, 22 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-502 | |
Metrics |
cvssV3_1
|
Tue, 21 Jan 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
References |
|

Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2025-03-18T18:16:26.206Z
Reserved: 2024-10-18T00:37:30.555Z
Link: CVE-2024-49744

Updated: 2025-01-22T14:40:52.655Z

Status : Awaiting Analysis
Published: 2025-01-21T23:15:14.880
Modified: 2025-03-18T19:15:45.477
Link: CVE-2024-49744

No data.