{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T10:03:32.459","vulnerabilities":[{"cve":{"id":"CVE-2024-48336","sourceIdentifier":"cve@mitre.org","published":"2024-11-04T18:15:05.027","lastModified":"2026-06-17T07:58:25.753","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation."},{"lang":"es","value":" La función install() de ProviderInstaller.java en Magisk App anterior a la versión Canary 27007 no verifica la aplicación GMS antes de cargarla, lo que permite que una aplicación local no confiable sin privilegios adicionales ejecute silenciosamente código arbitrario en la aplicación Magisk y escale privilegios a root a través de un paquete manipulado, también conocido como error n.° 8279. No se necesita interacción del usuario para la explotación."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"magisk","product":"magisk","defaultStatus":"unknown","cpes":["cpe:2.3:a:magisk:magisk:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"canary27007","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-04T19:05:31.240898Z","id":"CVE-2024-48336","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-829"}]}],"references":[{"url":"https://github.com/canyie/MagiskEoP","source":"cve@mitre.org"},{"url":"https://github.com/topjohnwu/Magisk/commit/c2eb6039579b8a2fb1e11a753cea7662c07bec02","source":"cve@mitre.org"}]}}]}