{"id":"ASB-A-304772709","details":"In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-304772709","CVE-2024-34734"],"modified":"2026-05-22T15:55:21.353668239Z","published":"2024-08-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2024-08-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/base/+/207584fb6f820eba14251251d7e9331bfd57adb8"}],"affected":[{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14-next:0"},{"fixed":"14-next:2024-08-01"}]}],"versions":["14-next"],"ecosystem_specific":{"spl":"2024-08-01","severity":"High","types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/d7628d5621c912399cefcddd9977199d62df320c"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-304772709.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2024-08-01"}]}],"versions":["13"],"ecosystem_specific":{"vanir_signatures":[{"signature_type":"Line","signature_version":"v1","id":"ASB-A-304772709-2376c493","source":"https://android.googlesource.com/platform/frameworks/base/+/0fddfa039dffd62f354def04e43d5a3ef0364aa8","target":{"file":"packages/SystemUI/src/com/android/systemui/qs/QSFgsManagerFooter.java"},"deprecated":false,"digest":{"line_hashes":["115231349495699315699779468554136138118","92493873096441502343598857152549941210","100186582344840127429326886486010969001","113737588290750270747933833788937747008","310618602047635826148618494921283769293","38695405348079907356614737515343236610","196395890817595194216298036881746627756","271216077679622555779868790440345352124","283337992116439958031158857384421565913","193419713536253332302289671525516396771","22698314509942089571370205522881231234","109375020268026493954714837942047141658","91876399156190887515676313717605658387","277109456149115836569775507779706322886","92414129479279785705974712045243112432","125138831783249741951846658780893478020","217232682108332789515422013223698448238","12302938611638037616699273122722730424","325257956032034794955954897920831573653","259545442593105390840273594050459980732"],"threshold":0.9}},{"signature_type":"Function","digest":{"length":659,"function_hash":"120738575144256579416902070950341571364"},"id":"ASB-A-304772709-e8d11570","source":"https://android.googlesource.com/platform/frameworks/base/+/0fddfa039dffd62f354def04e43d5a3ef0364aa8","target":{"function":"QSFgsManagerFooter","file":"packages/SystemUI/src/com/android/systemui/qs/QSFgsManagerFooter.java"},"deprecated":false,"signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","id":"ASB-A-304772709-ff8ce487","source":"https://android.googlesource.com/platform/frameworks/base/+/0fddfa039dffd62f354def04e43d5a3ef0364aa8","target":{"function":"onClick","file":"packages/SystemUI/src/com/android/systemui/qs/QSFgsManagerFooter.java"},"deprecated":false,"digest":{"length":83,"function_hash":"258980008619044602145318217345882527262"}}],"spl":"2024-08-01","severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/base/+/0fddfa039dffd62f354def04e43d5a3ef0364aa8"],"types":["EoP"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-304772709.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14:0"},{"fixed":"14:2024-08-01"}]}],"versions":["14"],"ecosystem_specific":{"spl":"2024-08-01","severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/base/+/598d7a18601a04b9904f0e170cc7c1777a3389ff"],"types":["EoP"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-304772709.json"}}],"schema_version":"1.7.5"}