In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | 13.0 (including) | 13.0 (including) | |
Android | 14.0 (including) | 14.0 (including) | |
Android | 15.0 (including) | 15.0 (including) |