CVE-2024-31328 describes a logic error in Google Android's BroadcastController.java that allows for the unauthorized launch of arbitrary activities on a paired companion phone from the background. This vulnerability affects Google Android products. The severity is rated as HIGH (CVSS 8.8), indicating a significant risk. It requires no user interaction or additional execution privileges, and the attack vector is adjacent network (AV:A), making it relatively easy to exploit with high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor is public exploit code available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage are minimal, suggesting low public awareness of this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.0CPE matchmatch criteria | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* | ||
16.0CPE matchmatch criteria | cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.