Lucene search

K
osvGoogleOSV:ASB-A-209966086
HistoryApr 01, 2022 - 12:00 a.m.

App can remain foreground forever without showing any notification and can bypass one time permissions. android.app.cts.NotificationManagerTest#testNotify_blockedChannelGroup

2022-04-0100:00:00
Google
osv.dev
2

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for OSV:ASB-A-209966086