2025-02-18 21:04:14 +00:00

25 lines
1.3 KiB
JSON

{
"id": "CVE-2024-49734",
"sourceIdentifier": "security@android.com",
"published": "2025-01-21T23:15:14.307",
"lastModified": "2025-02-18T20:15:20.197",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a VPN due to side channel information disclosure. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation."
},
{
"lang": "es",
"value": "En varias funciones de ConnectivityService.java, existe una forma posible para que un punto de acceso Wi-Fi determine a qu\u00e9 sitio se ha conectado un dispositivo a trav\u00e9s de una VPN debido a la divulgaci\u00f3n de informaci\u00f3n del canal lateral. Esto podr\u00eda generar una divulgaci\u00f3n de informaci\u00f3n remota sin necesidad de privilegios de ejecuci\u00f3n adicionales. No se necesita la interacci\u00f3n del usuario para la explotaci\u00f3n."
}
],
"metrics": {},
"references": [
{
"url": "https://source.android.com/security/bulletin/2025-01-01",
"source": "security@android.com"
}
]
}