Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35cj-v3wc-rh8w

Опубликовано: 16 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-173025705

In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-173025705

EPSS

Процентиль: 2%
0.00013
Низкий

Связанные уязвимости

CVSS3: 7.8
nvd
около 4 лет назад

In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-173025705

EPSS

Процентиль: 2%
0.00013
Низкий