In NFC, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privilege…
In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could l…
In SmsController, there is a possible information disclosure due to a permissions bypass. This could lead to local escalation of privilege and sendin…
In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This could lead to local escalati…
In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no…
In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission check. This could lead to local e…
In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation of privilege with no additio…
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with User execution privi…
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.…
In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. Thi…
In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could lead to local information disc…
In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosure. This could lead to local i…
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional exe…
In People, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. T…
In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This co…
In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This coul…
In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call stat…
In Keymaster, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System exe…
In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to loc…
In PermissionController, there is a possible way to delete some local files due to an unsafe PendingIntent. This could lead to local escalation of pr…
In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local …
In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to loca…
In Bubbles, there is a possible way to interfere with Bubbles due to a permissions bypass. This could lead to local escalation of privilege with no a…
In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to lo…
In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no addit…
In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional ex…
In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lead to local information disclo…
In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disc…
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information …