CVE-2024-0021

Publication date

2024-02-16 19:33:31

Family

google_android

State

PUBLISHED

Description

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.