
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability in the Android System component that could allow a possible notification listener grant to an app running in the work profile due to a logic error in the code. The vulnerability is tracked as CVE-2024-0043 and affects Android versions 12, 12L, 13, and 14 (Android Bulletin).
The vulnerability is classified as an Elevation of Privilege (EoP) issue with High severity. It exists in the Permission Controller component of Android and was addressed in the May 2024 security patch level (Android Bulletin).
The vulnerability could allow a work profile application to gain unauthorized access to notification listening capabilities, potentially leading to information disclosure or privilege escalation (Android Bulletin).
The vulnerability requires local access and no additional execution privileges are needed to exploit it. It has been given a High severity rating, suggesting significant potential impact if exploited (Android Bulletin).
The vulnerability has been patched in the May 2024 Android security update. Users should update their devices to a security patch level of 2024-05-01 or later to address this issue. The fix has been implemented in the Permission Controller component through Google Play system updates (Android Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."