CVE-2024-0038
EUVD-2024-1584116.02.2024, 02:15
In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| android | 14.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration