Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg4j-gvwp-3f8g

Опубликовано: 13 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-183147114

In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-183147114

EPSS

Процентиль: 1%
0.0001
Низкий

7.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.8
nvd
почти 4 года назад

In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-183147114

EPSS

Процентиль: 1%
0.0001
Низкий

7.8 High

CVSS3

Дефекты

CWE-863