Rewterz
Chinese Cyber Espionage Threat Groups Targeted SEA Government Agency – Active IOCs
June 6, 2024
Rewterz
Threat Actor Claims to Have Breached Dubai Government Systems with Ransomware
June 6, 2024

Multiple Google Android Framework Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-31314 CVSS:6.2

Google Android is vulnerable to a denial of service, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to cause a denial of service.

CVE-2024-31312 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2024-31326 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2024-31325 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2024-31324 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2024-31322 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2024-31319 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2024-31318 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2024-31317 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2024-31316 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2024-31310 CVSS:8.4

Google Android could allow a local attacker to gain elevated privileges on the system, caused by an error in the Framework component. By sending a specially crafted request, an attacker could exploit this vulnerability to gain elevated privileges on the system.

Impact

  • Denial of Service
  • Privilege Escalation

Indicators of Compromise

CVE

  • CVE-2024-31314
  • CVE-2024-31312
  • CVE-2024-31326
  • CVE-2024-31325
  • CVE-2024-31324
  • CVE-2024-31322
  • CVE-2024-31319
  • CVE-2024-31318
  • CVE-2024-31317
  • CVE-2024-31316
  • CVE-2024-31310

Affected Vendors

Google Android

Affected Products

  • Google Android 12
  • Google Android 13
  • Google Android 14

Remediation

Upgrade to the latest version of Android, available from the Google Website.

Google Website