CVE-2024-0043
NixOS vulnerability analysis and mitigation

Overview

A vulnerability in the Android System component that could allow a possible notification listener grant to an app running in the work profile due to a logic error in the code. The vulnerability is tracked as CVE-2024-0043 and affects Android versions 12, 12L, 13, and 14 (Android Bulletin).

Technical details

The vulnerability is classified as an Elevation of Privilege (EoP) issue with High severity. It exists in the Permission Controller component of Android and was addressed in the May 2024 security patch level (Android Bulletin).

Impact

The vulnerability could allow a work profile application to gain unauthorized access to notification listening capabilities, potentially leading to information disclosure or privilege escalation (Android Bulletin).

Exploitability

The vulnerability requires local access and no additional execution privileges are needed to exploit it. It has been given a High severity rating, suggesting significant potential impact if exploited (Android Bulletin).

Mitigation and workarounds

The vulnerability has been patched in the May 2024 Android security update. Users should update their devices to a security patch level of 2024-05-01 or later to address this issue. The fix has been implemented in the Permission Controller component through Google Play system updates (Android Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85706CRITICAL10
  • GitLab logoGitLab
  • gitlab
YesYesSep 12, 2026
CVE-2026-88009HIGH8.8
  • NixOS logoNixOS
  • github.com/traefik/traefik/v2
NoYesSep 10, 2026
CVE-2026-88008HIGH7
  • NixOS logoNixOS
  • github.com/traefik/traefik/v2
NoYesSep 10, 2026
CVE-2026-88012MEDIUM5.3
  • NixOS logoNixOS
  • traefik-fips-3
NoYesSep 10, 2026
CVE-2026-88011MEDIUM5.3
  • NixOS logoNixOS
  • github.com/traefik/traefik/v2
NoYesSep 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management