In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on the paired companion phone due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Mar 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android |
|
| CPEs | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:* |
|
| Vendors & Products |
Google
Google android |
Mon, 02 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV3_1
|
Mon, 02 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on the paired companion phone due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published: 2026-03-02T19:02:50.846Z
Updated: 2026-03-03T04:56:23.046Z
Reserved: 2024-03-29T20:12:39.974Z
Link: CVE-2024-31328
Updated: 2026-03-02T19:28:03.638Z
Status : Analyzed
Published: 2026-03-02T19:16:24.200
Modified: 2026-03-03T13:29:04.940
Link: CVE-2024-31328
No data.