VDB
CVE-2024-10382
CVE-2024-10382
PUBLISHED
CVSS 7.300000190734863 HIGH
There exists a code execution vulnerability in the Car App Android Jetpack Library. In the CarAppService desrialization logic is used that allows for arbitrary java classes to be constructed. In combination with other gadgets, this can lead to arbitrary code execution. An attacker needs to have an app on a victims Android device that uses the CarAppService Class and the victim would need to install a malicious app alongside it. We recommend upgrading the library past version 1.7.0-beta02
EPSS 0.15% · 5.0th percentile
Risk Scores
CVSS 4.0
7.300000190734863
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:N/R:U/V:C/RE:M/U:Amber
EPSS Score
0.15%
5.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| android | 1.4.0, 1.4.0, 1.4.0 | |
| Android | 1.4.0, 1.4.0 | |
| androidx.car.app | 0, 1.7.0, 1.7.0 |
Timeline
- Nov 20, 2024 Coalition ESS Score
- Nov 20, 2024 Coalition ESS Score
- Nov 20, 2024 CVE Published
- Nov 20, 2024 PoC Published
- Nov 20, 2024 PoC Published
- Nov 21, 2024 EPSS Score
- Dec 9, 2024 EPSS Score
- Dec 27, 2024 EPSS Score
- Jan 13, 2025 EPSS Score
- Jan 31, 2025 EPSS Score
- Feb 17, 2025 EPSS Score
- Mar 7, 2025 EPSS Score