In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Android | 14.0 (including) | 14.0 (including) | |
| Android | 15.0 (including) | 15.0 (including) | |
| Android | 16.0 (including) | 16.0 (including) | |
| Android | 16.0-qpr2_beta_1 (including) | 16.0-qpr2_beta_1 (including) | |
| Android | 16.0-qpr2_beta_2 (including) | 16.0-qpr2_beta_2 (including) | |
| Android | 16.0-qpr2_beta_3 (including) | 16.0-qpr2_beta_3 (including) |