← Back to CVE List

CVE-2024-48336

Published: 2024-11-04T18:15Z
Last Modified: 2024-11-04T20:35Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt