Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h79q-qqcc-qw9h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In onCreate of HandleApiCalls.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege that allows an app to set or dismiss the alarm with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150612638

In onCreate of HandleApiCalls.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege that allows an app to set or dismiss the alarm with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150612638

EPSS

Процентиль: 2%
0.00014
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
около 5 лет назад

In onCreate of HandleApiCalls.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege that allows an app to set or dismiss the alarm with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150612638

EPSS

Процентиль: 2%
0.00014
Низкий

Дефекты

CWE-269