In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.
References
| Link | Resource |
|---|---|
| https://android.googlesource.com/platform/frameworks/base/+/d6f7188773409c8f5ad5fc7d3eea5b1751439e26 | Mailing List Patch |
| https://source.android.com/security/bulletin/2024-02-01 | Patch Vendor Advisory |
| https://android.googlesource.com/platform/frameworks/base/+/d6f7188773409c8f5ad5fc7d3eea5b1751439e26 | Mailing List Patch |
| https://source.android.com/security/bulletin/2024-02-01 | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-02-16 02:15
Updated : 2025-03-28 16:15
NVD link : CVE-2024-0041
Mitre link : CVE-2024-0041
CVE.ORG link : CVE-2024-0041
JSON object : View
Products Affected
- android
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
