Lucene search

K
osvGoogleOSV:ASB-A-155094269
HistorySep 01, 2020 - 12:00 a.m.

All telephony code PendingIntent should use FLAG_IMMUTABLE to prevent security hole

2020-09-0100:00:00
Google
osv.dev
7

0.0004 Low

EPSS

Percentile

5.1%

In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

References

0.0004 Low

EPSS

Percentile

5.1%

Related for OSV:ASB-A-155094269