Lucene search

K
osvGoogleOSV:ASB-A-299931761
HistoryApr 01, 2024 - 12:00 a.m.

Bypass DISALLOW_ADD_WIFI_CONFIG to connect to an untrusted Wi-Fi network by WifiDialogActivity

2024-04-0100:00:00
Google
osv.dev
15
bypass
disallow_add_wifi_config
wifidialogactivity
missing permission check
local privilege escalation
untrusted wi-fi network
software

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for OSV:ASB-A-299931761