Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-31332

CVE-2024-31332: Google Android Privilege Escalation Flaw

CVE-2024-31332 is a privilege escalation vulnerability in Google Android that allows attackers to bypass Wi-Fi connection restrictions. This article covers the technical details, affected versions, impact, and mitigation.

Published:

CVE-2024-31332 Overview

CVE-2024-31332 is a local privilege escalation vulnerability in Google Android affecting multiple locations in the Settings application. The flaw stems from a missing permission check that allows local applications to bypass a restriction on adding new Wi-Fi connections. Successful exploitation grants elevated capabilities without requiring additional execution privileges or user interaction. Google addressed the issue in the July 2024 Android Security Bulletin. The vulnerability is tracked under [CWE-862: Missing Authorization].

Critical Impact

A local application can add new Wi-Fi connections without holding the required permission, leading to local privilege escalation on Android 13 and Android 14 devices.

Affected Products

  • Google Android 13.0
  • Google Android 14.0
  • Android Open Source Project (AOSP) Settings component

Discovery Timeline

  • 2024-07-01 - Google publishes fix in the Android Security Bulletin July 2024
  • 2024-07-09 - CVE-2024-31332 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-31332

Vulnerability Analysis

The vulnerability resides in Android's Settings package, specifically in code paths that handle Wi-Fi network configuration. Android enforces the CHANGE_WIFI_STATE and related permissions to restrict which applications can add or modify saved Wi-Fi networks. The affected code paths fail to verify the caller's permission before allowing new Wi-Fi connection entries to be added. A local unprivileged application can invoke these entry points and register attacker-controlled network configurations. The device treats the added networks as user-approved, extending the attacker's control over network selection and connectivity behavior.

Root Cause

The root cause is a missing authorization check ([CWE-862]) in multiple locations within the Settings app. Developers assumed the calling context already carried the required permission, but the code path can be reached from lower-privileged components. The fix, tracked in Android Settings Commit d1f9e61e, adds the appropriate permission enforcement before mutating the Wi-Fi configuration store.

Attack Vector

Exploitation requires a locally installed application with low privileges. The malicious app calls the exposed Settings interfaces that handle Wi-Fi additions. Because no permission check is performed, the request succeeds and the attacker's Wi-Fi profile is added to the device. This enables downstream attacks such as forcing the device onto attacker-controlled networks, facilitating man-in-the-middle interception, or persisting rogue network entries for later use. No user interaction is required during exploitation.

No public proof-of-concept or exploit code is available at the time of publication, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2024-31332

Indicators of Compromise

  • Unexpected Wi-Fi network entries appearing in the device's saved networks list without user action.
  • Installed applications requesting or invoking Wi-Fi configuration APIs without declaring CHANGE_WIFI_STATE in their manifest.
  • Devices repeatedly associating with unknown SSIDs after installing a specific third-party application.

Detection Strategies

  • Inspect application manifests and runtime behavior for calls to Settings Wi-Fi configuration endpoints that lack declared permissions.
  • Correlate mobile device management (MDM) telemetry on saved Wi-Fi profile changes with the installing application's identity and install time.
  • Review Android build numbers against the July 2024 patch level and flag devices below the fixed security patch level.

Monitoring Recommendations

  • Enroll Android 13 and 14 devices into MDM or Unified Endpoint Management (UEM) tooling and alert on security patch level below 2024-07-01.
  • Monitor for sideloaded APKs and untrusted app sources on managed fleets.
  • Track anomalous Wi-Fi association patterns and unexpected changes to saved network lists across the fleet.

How to Mitigate CVE-2024-31332

Immediate Actions Required

  • Update affected Android 13 and Android 14 devices to a security patch level of 2024-07-01 or later.
  • Restrict application installation to trusted sources such as Google Play and remove sideloaded or unverified applications.
  • Audit installed applications on managed devices for those requesting Wi-Fi related capabilities.

Patch Information

Google released a fix as part of the July 2024 Android Security Bulletin. The upstream source change is documented in the Android Settings commit d1f9e61e, which adds the missing permission check before Wi-Fi configuration modifications. OEM device vendors incorporate this fix into their monthly security updates. Refer to the Android Security Bulletin July 2024 for OEM-specific guidance.

Workarounds

  • Enforce MDM policies that block installation of applications from unknown sources on Android 13 and 14 devices.
  • Configure enterprise Wi-Fi profiles through MDM and periodically reconcile the saved networks list against the approved baseline.
  • Delay deployment of untrusted third-party applications on unpatched devices until the July 2024 or later security patch is applied.
bash
# Verify the Android security patch level on a device via adb
adb shell getprop ro.build.version.security_patch
# Expected output for patched devices: 2024-07-01 or later

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.