Lucene search

K
osvGoogleOSV:ASB-A-282934003
HistoryJan 01, 2024 - 12:00 a.m.

Enable notification listener services in the work profile via CompanionDeviceManager#requestNotificationAccess

2024-01-0100:00:00
Google
osv.dev
11
companiondevicemanager
notificationaccessconfirmationactivity
logic error
local escalation
user interaction
privilege escalation

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for OSV:ASB-A-282934003