Описание
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege and the setting of supported EUICC countries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253476
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
EPSS
Процентиль: 1%
0.00012
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-862
Связанные уязвимости
github
больше 3 лет назад
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege and the setting of supported EUICC countries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253476
EPSS
Процентиль: 1%
0.00012
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-862