In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://source.android.com/security/bulletin/pixel/2024-03-01 | Vendor Advisory |
| https://source.android.com/security/bulletin/pixel/2024-03-01 | Vendor Advisory |
Configurations
History
03 Apr 2025, 15:54
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://source.android.com/security/bulletin/pixel/2024-03-01 - Vendor Advisory | |
| First Time |
Google android
|
|
| CPE | cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* |
11 Mar 2024, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-03-11 19:15
Updated : 2025-04-03 15:54
NVD link : CVE-2024-27233
Mitre link : CVE-2024-27233
JSON object : View
Products Affected
- android
CWE
No CWE.
