In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motion events to the default IME d…
In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local i…
In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lea…
In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permissi…
In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission c…
In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to loca…
In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission …
In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privi…
In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission…
In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local es…
In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead …
In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead …
In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul…
In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the access…
In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due …
In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc…
In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure w…
In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no a…
In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission chec…
In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This …
In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of p…
In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing pe…
In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. …
In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. This could …
In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check.…
In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution pri…
In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System executi…
In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission…
In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could le…
In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local…