CVE-2024-48336
Last modified
CVE-2024-48336 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation.. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-48336?
How severe is CVE-2024-48336?
How do I fix CVE-2024-48336?
Are you affected by CVE-2024-48336?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
