CVE-2024-0015: In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This...

7.8 CVSS

Description

In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

Classification

CVE ID: CVE-2024-0015

CVSS Base Severity: HIGH

CVSS Base Score: 7.8

Problem Types

Elevation of privilege

Affected Products

Vendor: Google

Product: Android

Exploit Prediction Scoring System (EPSS)

EPSS Score: 1.88% (probability of being exploited)

EPSS Percentile: 81.64% (scored less or equal to compared to others)

EPSS Date: 2025-04-12 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: total

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-0015
https://android.googlesource.com/platform/frameworks/base/+/2ce1b7fd37273ea19fbbb6daeeaa6212357b9a70
https://source.android.com/security/bulletin/2024-01-01

Timeline