Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqg6-vqf5-9pf3

Опубликовано: 13 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

EPSS

Процентиль: 20%
0.00066
Низкий

8.4 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.8
nvd
около 1 года назад

In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

EPSS

Процентиль: 20%
0.00066
Низкий

8.4 High

CVSS3

Дефекты

CWE-862