CVE-2024-0020
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Feb 16, 2024
Updated: Dec 16, 2024
Summary
CVE-2024-0020 is a local information disclosure vulnerability affecting NotificationSoundPreference.java's onActivityResult function. A confused deputy condition allows an attacker to access audio files belonging to different users on the same device, without requiring additional execution privileges or user interaction. This vulnerability could potentially lead to sensitive information being exposed across user accounts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Android