In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information …
In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local in…
In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local in…
In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to …
In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lea…
In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosu…
In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query permissions due to side channel …
In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure…
In PermissionController, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with U…
In AudioService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclos…
In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. Th…
In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could…
In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could le…
A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typically a developer) manually in…
On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files …
In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of k…
A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded i…
Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A
In copy_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privil…
In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check…
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to loca…
In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with Syst…
In ProtocolStkProactiveCommandAdapter::Init of protocolstkadapter.cpp, there is a possible out of bounds write due to an incorrect bounds check. This…
In amcs_cdev_unlocked_ioctl of audiometrics.c, there is a possible out of bounds write due to improper input validation. This could lead to local esc…
In prepare_io_entry and prepare_response of lwis_ioctl.c and lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. …
In gasket_alloc_coherent_memory of gasket_page_table.c, there is a possible memory corruption due to a race condition. This could lead to local escal…
In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escal…
Product: AndroidVersions: Android kernelAndroid ID: A-202160245References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-207433926References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A