CVE-2024-31320
NixOS vulnerability analysis and mitigation

Overview

CVE-2024-31320 is a security vulnerability in Android's companion device association functionality, specifically in the setSkipPrompt method of AssociationRequest.java. The vulnerability was discovered and disclosed on July 9, 2024, affecting Android versions 12.0 and 12.1. This vulnerability allows unauthorized companion device association without requiring confirmation through CDM (Companion Device Manager) (NVD).

Technical details

The vulnerability exists in the setSkipPrompt functionality of AssociationRequest.java, which improperly handles companion device associations. It has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating local access with low attack complexity and no user interaction required. The vulnerability is classified under CWE-284 (Improper Access Control) and CWE-269 (Improper Privilege Management) (NVD).

Impact

The vulnerability enables local escalation of privilege without requiring additional execution privileges. An attacker could potentially establish unauthorized companion device associations, bypassing the normal confirmation process, which could lead to unauthorized access to device features and data (NVD).

Mitigation and workarounds

Google has addressed this vulnerability through security patches, with fixes implemented in the Android codebase. The patches include modifications to both AssociationRequest.java and CompanionDeviceManagerService.java to prevent unauthorized skipping of confirmation prompts (Android Source, Android Source).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management