In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 18 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Title | OOB Read in the android.hardware.boot.IBootControl/default service | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google_Devices
Published: 2024-12-18T19:04:29.409Z
Updated: 2024-12-18T19:16:43.518Z
Reserved: 2024-09-16T19:21:19.200Z
Link: CVE-2024-47039
Updated: 2024-12-18T19:16:39.804Z
Status : Analyzed
Published: 2024-12-18T19:15:10.850
Modified: 2025-07-24T18:02:08.630
Link: CVE-2024-47039
No data.