CVE-2024-0020

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 16, 2024
Updated: Dec 16, 2024

Summary

CVE-2024-0020 is a local information disclosure vulnerability affecting NotificationSoundPreference.java's onActivityResult function. A confused deputy condition allows an attacker to access audio files belonging to different users on the same device, without requiring additional execution privileges or user interaction. This vulnerability could potentially lead to sensitive information being exposed across user accounts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share