Vulnerability Details
Basic Information
| Title | Exploit for Deserialization of Untrusted Data in Google Android |
|---|---|
| Type | githubexploit |
| Published | 2025-04-26T16:46:35 |
| Last Seen | 2025-04-26T21:03:37 |
| CVSS Score | 7.8 (HIGH) |
CVSS v3 Details
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2024-31317 |
|---|---|
| CWE | |
| Bulletin Family | exploit |
Description
Exploration of CVE-2024-31317 CVE-2024-31317 provides unpriviledged access to any uid and SELinux scope available to proper Android apps. This provides access to uid 1000 (system) and uid 2000 (shell), and can be triggered entirely from an…
Impact Assessment
| Base Score | 7.8 |
|---|---|
| Severity | HIGH |