CVE-2024-38425
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Oct 7, 2024
Updated: Oct 16, 2024
CWE ID 285
CWE ID 863
Summary
CVE-2024-38425 is a newly identified information disclosure vulnerability. It allows an attacker to gain access to sensitive information through implicit broadcasts containing APP launch data. This vulnerability occurs during the information exchange process between applications, potentially exposing details that should remain private. The impact of this issue could lead to unintended data leakage or further exploitation. It is recommended that affected systems are updated as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.