In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to loca…
In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalatio…
In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of pri…
In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due…
In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege …
In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check. This could lea…
In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to loc…
In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local …
In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to loca…
In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to lo…
In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disc…
In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to …
In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lea…
In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check…
In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This coul…
In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missi…
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no …
In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with …
In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System e…
In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing pe…
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no…
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no…
In system service, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no …
In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privi…
The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for i…
In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with …
In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead…
In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege w…
In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, du…
In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permis…