Lucene search

K
osvGoogleOSV:ASB-A-172939189
HistoryMay 01, 2021 - 12:00 a.m.

Arbitrary System App File Could be Copied to content://com.android.settings.files/ When Editing User Photo

2021-05-0100:00:00
Google
osv.dev
11

0.0005 Low

EPSS

Percentile

17.1%

In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

0.0005 Low

EPSS

Percentile

17.1%

Related for OSV:ASB-A-172939189