CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-0041: In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could...

7.0 CVSS

Description

In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.

Classification

CVE ID: CVE-2024-0041

CVSS Base Severity: HIGH

CVSS Base Score: 7.0

Problem Types

Elevation of privilege

Affected Products

Vendor: Google

Product: Android

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 4.21% (scored less or equal to compared to others)

EPSS Date: 2025-04-25 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: total

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-0041
https://android.googlesource.com/platform/frameworks/base/+/d6f7188773409c8f5ad5fc7d3eea5b1751439e26
https://source.android.com/security/bulletin/2024-02-01

Timeline