CVE-2024-2567

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 17, 2024
Updated: Aug 1, 2024
CWE ID 434

Summary

CVE-2024-2567 is a vulnerability affecting the jurecapuder AndroidWeatherApp 1.0.0 on Android. The issue lies within an unknown function of the androidmanifest.xml file in the Backup File Handler component. This manipulation allows unauthorized access to backup files, potentially exposing sensitive information. The exploit has been disclosed to the public, increasing the risk of attack. VDB-257070 is the assigned identifier for this vulnerability. Notably, this vulnerability only impacts unsupported versions of the software, as the maintainer did not respond to disclosure efforts and subsequently deleted the GitHub repository.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share