Lucene search

K
osvGoogleOSV:ASB-A-184046948
HistorySep 01, 2021 - 12:00 a.m.

HeapDumpProvider is open to any app

2021-09-0100:00:00
Google
osv.dev
8

0.0004 Low

EPSS

Percentile

5.1%

In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CPENameOperatorVersion
platform/frameworks/baseeq11

0.0004 Low

EPSS

Percentile

5.1%

Related for OSV:ASB-A-184046948