CVE-2024-34739
https://notcve.org/view.php?id=CVE-2024-34739
In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. • https://github.com/uthrasri/CVE-2024-34739 https://android.googlesource.com/platform/frameworks/base/+/50e1f8f36e32928d10e72324c05a203a6db9f7fb https://source.android.com/security/bulletin/2024-08-01 • CWE-116: Improper Encoding or Escaping of Output •
CVE-2024-34738
https://notcve.org/view.php?id=CVE-2024-34738
In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. • https://android.googlesource.com/platform/frameworks/base/+/21d764807b3dcd402d63e2b4c9fbae1c9965400a https://source.android.com/security/bulletin/2024-08-01 •
CVE-2024-34737
https://notcve.org/view.php?id=CVE-2024-34737
In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. • https://android.googlesource.com/platform/frameworks/base/+/8b473b3f79642f42eeeffbfe572df6c6cbe9d79e https://source.android.com/security/bulletin/2024-08-01 •
CVE-2024-34736
https://notcve.org/view.php?id=CVE-2024-34736
In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-frame support is enabled. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. • https://android.googlesource.com/platform/frameworks/av/+/6cfd048292b2cc706811a22c9078208cfa8e6d24 https://source.android.com/security/bulletin/2024-08-01 •
CVE-2024-34734
https://notcve.org/view.php?id=CVE-2024-34734
In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. • https://android.googlesource.com/platform/frameworks/base/+/207584fb6f820eba14251251d7e9331bfd57adb8 https://source.android.com/security/bulletin/2024-08-01 • CWE-1188: Initialization of a Resource with an Insecure Default •