In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-10, Android-11, Android-8.0, Android-8.1, Android-9; Android ID: A-168319670.
The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | 8.0 | 8.0 | |
Android | 8.1 | 8.1 | |
Android | 9.0 | 9.0 | |
Android | 10.0 | 10.0 | |
Android | 11.0 | 11.0 |