Lucene search

K
osvGoogleOSV:ASB-A-172935267
HistoryFeb 01, 2021 - 12:00 a.m.

getContentProviderImpl returns without Binder.restoreCallingIdentity, allowing starting any activities

2021-02-0100:00:00
Google
osv.dev
6

0.0004 Low

EPSS

Percentile

5.1%

In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

0.0004 Low

EPSS

Percentile

5.1%

Related for OSV:ASB-A-172935267