CVE-2024-49734

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 21, 2025
Updated: Jan 22, 2025
CWE ID 203

Summary

CVE-2024-49734 is a newly disclosed vulnerability affecting multiple functions in ConnectivityService.java. This issue stems from side channel information disclosure, allowing a Wi-Fi Access Point (AP) to infer what site a device has connected to via a VPN. The implications of this vulnerability are significant, as it enables remote information disclosure without the need for any additional execution privileges or user interaction. Essentially, an attacker can exploit this flaw to gain insights into a user's online activities, potentially putting their privacy at risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share