7.8
CVSSv3

CVE-2024-49742

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: NA | VMScore: 880 | EPSS: 0.00043 | KEV: Not Included
Published: 21/01/2025 Updated: 22/01/2025

Vulnerability Summary

Local Privilege Escalation via Missing Permission Check in Android

In onCreate of NotificationAccessConfirmationActivity.java, there is a way to hide an app with notification access in Settings because a permission check is missing. This can cause local escalation of privilege without requiring extra execution privileges. User interaction is necessary for this exploit.

Vulnerable Product Search on Vulmon Subscribe to Product

google android