CVE-2024-31335 is a high-severity arbitrary code execution vulnerability affecting Google Android, stemming from a logic error in the DevmemIntChangeSparse2 function within devicemem_server.c. This flaw allows for local escalation of privilege within the kernel without requiring user interaction or additional execution privileges. With a CVSS score of 7.8, it presents a significant risk of complete compromise of confidentiality, integrity, and availability. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.