Lucene search

K
osvGoogleOSV:ASB-A-299614635
HistoryJan 01, 2024 - 12:00 a.m.

[STS SDK Grant] Security Report - Reveal audios across users via com.android.settings.notification.app.NotificationSoundPreference

2024-01-0100:00:00
Google
osv.dev
12
security
notification
audio
users
confused deputy
information disclosure
user interaction
android

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed. User interaction is not needed for exploitation.

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for OSV:ASB-A-299614635