CVE-2024-49734
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-49734 is a newly disclosed vulnerability affecting multiple functions in ConnectivityService.java. This issue stems from side channel information disclosure, allowing a Wi-Fi Access Point (AP) to infer what site a device has connected to via a VPN. The implications of this vulnerability are significant, as it enables remote information disclosure without the need for any additional execution privileges or user interaction. Essentially, an attacker can exploit this flaw to gain insights into a user's online activities, potentially putting their privacy at risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Android