Описание
In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
EPSS
Процентиль: 2%
0.00121
Низкий
6.7 Medium
CVSS3
Дефекты
CWE-441
Связанные уязвимости
CVSS3: 7.8
github
3 дня назад
In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
EPSS
Процентиль: 2%
0.00121
Низкий
6.7 Medium
CVSS3
Дефекты
CWE-441