Lucene search

K
osvGoogleOSV:ASB-A-272025416
HistoryNov 01, 2023 - 12:00 a.m.

ADP Grant - Detecting photos belonging to other users via SystemUI Controls with ThumbnailTemplate

2023-11-0100:00:00
Google
osv.dev
14
adp grant
unauthorized access
systemui controls
cross-user read
local information disclosure
photos
images
exploitation
software

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.0%

In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.0%

Related for OSV:ASB-A-272025416