← Back to CVE List

CVE-2024-40652

Published: 2024-09-11T00:15Z
Last Modified: 2024-12-17T19:09Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt