In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission c…
In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications into a newly created work prof…
In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of pri…
In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege…
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the pr…
In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most commonly used in Work Profile scena…
In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to loca…
In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in the code.…
In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This could lead…
In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logi…
In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This could lead to local escalati…
In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additiona…
In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app when its result will be used in …
In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This could lead to remote denial of se…
In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. This could…
In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlay attack.…
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due to a logic…
In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak through the lockscreen due to a log…
In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissions due to a logic error in t…
In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additio…
In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy. This could lead to local inf…
In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused deputy. This could lead to lo…
In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error…
In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has …
In mbrain, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has alr…
In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code exec…
In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (prox…
In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adja…
In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalati…
In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege wi…