In RestrictionsManager, there is a possible way to send a broadcast that should be restricted to system apps due to a permissions bypass. This could …
In Bluetooth, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System …
In Bluetooth, there is a possible cleanup failure due to an uncaught exception. This could lead to remote denial of service in Bluetooth with no addi…
In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execu…
In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no ad…
In the Phone app, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app w…
In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disc…
In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to impro…
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-184676385References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-210916981References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-204782372References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no …
Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A
In AllocateInternalBuffers of g3aa_buffer_allocator.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local …
Product: AndroidVersions: Android kernelAndroid ID: A-212625740References: N/A
In SAEMM_RetrievEPLMNList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remo…
Product: AndroidVersions: Android kernelAndroid ID: A-205714161References: N/A
In trusty_log_seq_start of trusty-log.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege…
In TBD of keymaster_ipc.cpp, there is a possible to force gatekeeper, fingerprint, and faceauth to use a known HMAC key. This could lead to local esc…
In lwis_buffer_alloc of lwis_buffer.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of p…
In (TBD) of (TBD), there is a possible out of bounds write due to kernel stack overflow. This could lead to local escalation of privilege with System…
Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A
In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check…
In Settings, there is a possible way to connect to an open network bypassing DISALLOW_CONFIG_WIFI restriction due to a logic error in the code. This …
In Messaging, there is a possible way to attach files to a message without proper access checks due to improper input validation. This could lead to …