In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no addit…
In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privi…
In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege …
In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of privilege w…
In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privileg…
In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of privilege wi…
In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to local escalation of privilege…
In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of serv…
In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System exe…
In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no…
In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no…
In SELinux Policy, there is a possible restriction bypass due to a permissions bypass. This could lead to local information disclosure with no additi…
In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permission check. …
In Settings, there is a possible way for the user to unintentionally send extra data due to an unclear prompt. This could lead to local information d…
In Package Manager, there is a possible possible permissions bypass due to an unsafe PendingIntent. This could lead to local information disclosure w…
In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional e…
In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from another user due to a missing permission check. Thi…
In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additio…
In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escala…
In the Security Element API, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege wit…
In Secure Element, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System e…
In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design. This could lead to local in…
In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information disclosure with no additional exec…
In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissions bypass. This could lead to…
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution wit…
In Bluetooth, there is a possibility of code-execution due to a use after free. This could lead to paired device escalation of privilege in the privi…
In multiple locations, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privil…
In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no addition…
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This …
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no addition…