In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Android | 13.0 (including) | 13.0 (including) | |
| Android | 14.0 (including) | 14.0 (including) |