CVE-2024-0245
CVSS 3.0 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-0245 is a newly discovered vulnerability affecting the hamza417/inure Android app before build97. The root cause is a misconfiguration in the AndroidManifest.xml file, which enables task hijacking. Malicious apps can exploit this weakness to inherit the permissions of the vulnerable app, posing a significant risk for the exposure of sensitive information. An attacker can create a malicious app that hijacks the legitimate Inure app, allowing them to intercept and steal data when installed on a victim's device. This issue poses a threat to all Android versions prior to Android 11.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.