CERT-In Vulnerability Note
CIVN-2024-0102
Multiple Vulnerabilities in Android
Original Issue Date:April 03, 2024
Severity Rating: HIGH
Software Affected
- Android Versions 12, 12L, 13, 14
Overview
Multiple vulnerabilities have been reported in Android which could be exploited by an attacker to obtain sensitive information, gain elevated privileges and cause denial of service condition on the targeted system.
Description
These vulnerabilities exist in Android due to flaws in the Framework, System, MediaTek components, Widevine, Qualcomm components and Qualcomm closed-source components.
Successful exploitation of these vulnerabilities could allow the attacker to obtain sensitive information, gain elevated privileges and cause denial of service condition on the targeted system.
Solution
Apply appropriate updates when made available by the respective OEMs:
https://source.android.com/docs/security/bulletin/2024-04-01
Vendor Information
Android
https://source.android.com/docs/security/bulletin/2024-04-01
References
Android
https://source.android.com/docs/security/bulletin/2024-04-01
CVE Name
CVE-2023-21267
CVE-2023-28547
CVE-2023-28582
CVE-2023-32890
CVE-2023-33023
CVE-2023-33084
CVE-2023-33086
CVE-2023-33095
CVE-2023-33096
CVE-2023-33099
CVE-2023-33100
CVE-2023-33101
CVE-2023-33103
CVE-2023-33104
CVE-2023-33115
CVE-2024-0022
CVE-2024-0026
CVE-2024-0027
CVE-2024-0042
CVE-2024-20039
CVE-2024-20040
CVE-2024-21463
CVE-2024-21468
CVE-2024-21472
CVE-2024-23704
CVE-2024-23710
CVE-2024-23712
CVE-2024-23713
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|