Share:
Notifications
Clear all

CVE-2024-0038

1 Posts
1 Users
0 Reactions
453 Views
(@cybersec)
Posts: 37
Eminent Member
Topic starter
 

Description

In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

 
Posted : 04/06/2024 12:50 am
Share: