CVE-2024-0017
CVE-2024-0017 is a vulnerability in CameraActivity.java that could lead to local information disclosure. Due to a permissions bypass vulnerability within the CameraActivity, a confused deputy issue exists. This vulnerability allows for local information disclosure without requiring elevated privileges. While the CVSS score is moderate, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a lower immediate risk than vulnerabilities with higher SVRS scores. User interaction is necessary for exploitation. This means an attacker needs to trick the user into performing an action to trigger the vulnerability. Despite the moderate CVSS and low SVRS, organizations should still assess and address this issue to prevent potential information leaks. The presence of the "In The Wild" tag also indicates it is worth investigating and prioritizing an update.
Description:
CVE-2024-0017 is a vulnerability in CameraActivity.java that could lead to local information disclosure. The vulnerability is caused by a possible confused deputy due to a permissions bypass. User interaction is needed for exploitation. The SOCRadar Risk Score (SVRS) for this vulnerability is 42, indicating a moderate level of severity.
Key Insights:
- The vulnerability could allow an attacker to access sensitive information on the affected device.
- The vulnerability is relatively easy to exploit, requiring only user interaction.
- The vulnerability is not currently being actively exploited in the wild.
- The CISA has not yet issued a warning about the vulnerability.
Mitigation Strategies:
- Update to the latest version of the affected software.
- Disable the affected feature until a patch is available.
- Use a mobile security solution to detect and block malicious activity.
- Educate users about the risks of interacting with untrustworthy applications.
Additional Information:
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.