In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission ch…
In Content, there is a possible way to determinate the user's account due to side channel information disclosure. This could lead to local informatio…
In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution over Bluetooth with no add…
In PermissionController, there is a possible way to grant some permissions without user consent due to misleading or insufficient UI. This could lead…
In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User executi…
In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of p…
In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation…
In Connectivity, there is a possible bypass the restriction of starting activity from background due to a logic error in the code. This could lead to…
In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no addition…
In Content, there is a possible way to learn gmail account name on the device due to a permissions bypass. This could lead to local information discl…
In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could l…
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information …
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information …
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information …
In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local inf…
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information …
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of phone …
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information discl…
In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informat…
In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informat…
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information dis…
In Midi, there is a possible way to learn about private midi devices due to a permissions bypass. This could lead to local escalation of privilege wi…
In AppOpsService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclo…
In Wi-Fi, there is a permissions bypass. This could lead to local escalation of privilege from the guest user with no additional execution privileges…
In Bluetooth, there is a possible way to bypass compiler exploit mitigations due to a configuration error. This could lead to local escalation of pri…
In RestrictionsManager, there is a possible way to send a broadcast that should be restricted to system apps due to a permissions bypass. This could …
In Bluetooth, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System …
In Bluetooth, there is a possible cleanup failure due to an uncaught exception. This could lead to remote denial of service in Bluetooth with no addi…
In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execu…
In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no ad…