We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-34720



Assignergoogle_android
Reserved2024-05-07
Published2024-07-09
Updated2024-08-02

Description

In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, there is a possible method to perform arbitrary code execution in any app zygote processes due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Problem types

Elevation of privilege

Product status

Default status
unaffected

14
affected

13
affected

12L
affected

12
affected

References

https://android.googlesource.com/platform/frameworks/base/+/293e9ac230851acbec73f5ab12928d113d6283e1

https://source.android.com/security/bulletin/2024-07-01

cve.org CVE-2024-34720

nvd.nist.gov CVE-2024-34720

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.