Логотип exploitDog
bind:CVE-2024-48336
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-48336

Количество 2

Количество 2

nvd логотип

CVE-2024-48336

больше 1 года назад

The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Средний
github логотип

GHSA-9xg5-55cm-9gxr

больше 1 года назад

The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-48336

The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation.

CVSS3: 8.4
13%
Средний
больше 1 года назад
github логотип
GHSA-9xg5-55cm-9gxr

The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation.

CVSS3: 8.4
13%
Средний
больше 1 года назад

Уязвимостей на страницу