In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Mar 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-20 | |
CPEs | cpe:2.3:o:google:android:13.0.0:*:*:*:*:*:*:* | |
Metrics |
ssvc
|
Mon, 25 Nov 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google android |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2025-03-27T20:52:59.434Z
Reserved: 2023-11-16T22:58:40.755Z
Link: CVE-2024-0022

Updated: 2024-08-01T17:41:15.522Z

Status : Modified
Published: 2024-05-07T21:15:08.330
Modified: 2025-03-27T21:15:43.683
Link: CVE-2024-0022

No data.