Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qf37-j9hx-38gx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In hasActivityInVisibleTask of WindowProcessController.java there?s a possible bypass of user interaction requirements due to incorrect handling of top activities in INITIALIZING state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-138583650

In hasActivityInVisibleTask of WindowProcessController.java there?s a possible bypass of user interaction requirements due to incorrect handling of top activities in INITIALIZING state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-138583650

EPSS

Процентиль: 1%
0.0001
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.8
nvd
около 6 лет назад

In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements due to incorrect handling of top activities in INITIALIZING state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-138583650

EPSS

Процентиль: 1%
0.0001
Низкий

Дефекты

CWE-20