Beveiligingsadvies

CVE-2024-34737

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-08-15 21:56:32
Laatst bijgewerkt 2025-03-25 15:54:24
Toegewezen door google_android
CVSS-score 7.7
Status PUBLISHED

Beschrijving

In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.