Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9vj-qvc7-4xjj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of Check/Time of Use condition. This could lead to local escalation of privilege by allowing a bypass of the initial zip file signature check for an OS update with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-136498130

In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of Check/Time of Use condition. This could lead to local escalation of privilege by allowing a bypass of the initial zip file signature check for an OS update with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-136498130

EPSS

Процентиль: 13%
0.00043
Низкий

Связанные уязвимости

CVSS3: 7
nvd
больше 5 лет назад

In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of Check/Time of Use condition. This could lead to local escalation of privilege by allowing a bypass of the initial zip file signature check for an OS update with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-136498130

EPSS

Процентиль: 13%
0.00043
Низкий