CVE-2024-40239
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Summary
CVE-2024-40239 is a newly discovered access control vulnerability in the Life: Personal Diary, Journal android app version 17.5.0. This issue allows a physically proximate attacker to exploit the fingerprint authentication function and escalate privileges beyond intended access levels. The inaccurate implementation of access controls in this app poses a significant security risk, enabling unauthorized users to gain sensitive information or even control the affected device. Users are strongly advised to update the app as soon as a patch is released to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.