CVE-2024-38425

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 7, 2024
Updated: Oct 16, 2024
CWE ID 285
CWE ID 863

Summary

CVE-2024-38425 is a newly identified information disclosure vulnerability. It allows an attacker to gain access to sensitive information through implicit broadcasts containing APP launch data. This vulnerability occurs during the information exchange process between applications, potentially exposing details that should remain private. The impact of this issue could lead to unintended data leakage or further exploitation. It is recommended that affected systems are updated as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share