CERT-In Vulnerability Note
CIVN-2024-0161
Multiple Vulnerabilities in Android
Original Issue Date:May 13, 2024
Severity Rating: HIGH
Software Affected
- Android versions 12, 12L, 13, 14
Overview
Multiple vulnerabilities have been reported in Android which could be exploited by an attacker to obtain sensitive information and gain elevated privileges on the targeted system.
Description
These vulnerabilities exist in Android due to flaws in the Framework, System, Google Play system updates, Kernel, Kernel LTS, Arm components, MediaTek components, Qualcomm components and Qualcomm closed-source components.
Successful exploitation of these vulnerabilities could allow the attacker to obtain sensitive information and gain elevated privileges on the targeted system.
Solution
Apply appropriate updates when made available by the respective OEMs:
https://source.android.com/docs/security/bulletin/2024-05-01
Vendor Information
Android
https://source.android.com/docs/security/bulletin/2024-05-01
References
Android
https://source.android.com/docs/security/bulletin/2024-05-01
CVE Name
CVE-2023-32871
CVE-2023-32873
CVE-2023-33119
CVE-2023-43529
CVE-2023-43530
CVE-2023-43531
CVE-2023-4622
CVE-2023-6363
CVE-2024-0024
CVE-2024-0025
CVE-2024-0043
CVE-2024-1067
CVE-2024-1395
CVE-2024-20056
CVE-2024-20057
CVE-2024-21471
CVE-2024-21475
CVE-2024-21477
CVE-2024-21480
CVE-2024-23351
CVE-2024-23354
CVE-2024-23705
CVE-2024-23706
CVE-2024-23707
CVE-2024-23708
CVE-2024-23709
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|