Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xh6v-cv6c-vgp6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147606347

In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147606347

EPSS

Процентиль: 9%
0.00034
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
больше 5 лет назад

In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147606347

EPSS

Процентиль: 9%
0.00034
Низкий

Дефекты

CWE-269