Lucene search

K
osvGoogleOSV:ASB-A-212286849
HistoryMar 01, 2022 - 12:00 a.m.

App can keep its service alive forever and can bypass one time permissions.

2022-03-0100:00:00
Google
osv.dev
5

7.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.6%

In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or permission due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

7.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.6%

Related for OSV:ASB-A-212286849