CVE-2024-40676

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Jan 28, 2025
Updated: Feb 6, 2025
CWE ID 843

Summary

CVE-2024-40676 is a vulnerability affecting the AccountManagerService.java in Android's AccountManager. In the function "checkKeyIntent", there's a confused deputy issue that allows an attacker to bypass intent security checks, enabling the installation of unauthorized apps. No additional execution privileges are required for exploitation, making this a local escalation of privilege vulnerability. User interaction is not necessary for an attacker to exploit this flaw.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share