In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel information disclosure. This could…
In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escala…
In multiple functions of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no …
In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission che…
In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confused deputy. This could lead t…
In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an intent redirect. This could l…
In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the …
In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local …
In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permission chec…
In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This could lead to local escalatio…
In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to…
In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to…
In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode…
In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additi…
In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on the paired …
In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …
In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (prox…
In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor …
In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor …
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al…
In display, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege if a malicious acto…
In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has al…
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious ac…
In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor…
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious ac…
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious ac…
In display, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a maliciou…
Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious ext…
Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access…