High severity7.8NVD Advisory· Published Jul 9, 2024· Updated Jun 17, 2026
CVE-2024-31320
CVE-2024-31320
Description
In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
3- android.googlesource.com/platform/frameworks/base/+/9722ce9d733edab76163fbcd21b231424e3d7061nvdMailing ListPatch
- android.googlesource.com/platform/frameworks/base/+/df49e0e3083b0707e2cca5a5956b49f14ded078envdMailing ListPatch
- source.android.com/security/bulletin/2024-07-01nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.