CVE-2024-31317

Published Jul 9, 2024

Last updated 4 months ago

Overview

Description
In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe deserialization. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Source
security@android.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-502
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-502

Social media

Hype score
Not currently trending
  1. The Android Zygote Processor Critical vulnerability CVE-2024-31317 The main issue is that the permission of any UID in the Android system can be obtained by using this vulnerability, which is similar to breaking through the Android sandbox and obtaining the permission of any htt

    @PPHM_HackerNews

    24 Mar 2025

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Actively exploited CVE : CVE-2024-31317

    @transilienceai

    17 Mar 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Actively exploited CVE : CVE-2024-31317

    @transilienceai

    15 Mar 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Severe Android Vulnerability CVE-2024-31317 Exposed! Attackers can exploit this flaw to gain unauthorized access, compromise sensitive data, and take control of devices. 🔹 High risk of malware, spyware, and data breaches. 🔹 Enterprises face compliance risks & security threa

    @Infosharenew

    12 Mar 2025

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Severe Android Vulnerability CVE-2024-31317 Exposed! Attackers can exploit this flaw to gain unauthorized access, compromise sensitive data, and take control of devices. 🔹 High risk of malware, spyware, and data breaches. 🔹 Enterprises face compliance risks & security threa

    @varutra

    12 Mar 2025

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. New vulnerability CVE-2024-31317 in Android Zygote allows system-wide code execution and privilege escalation on devices running Android 11 or older. ⚠️ Protect devices! #AndroidVulnerability #ZygoteInjection #USA link: https://t.co/EdHDxLZebe https://t.co/6MV0lij57S

    @TweetThreatNews

    11 Mar 2025

    28 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations