Lucene search

K
osvGoogleOSV:ASB-A-324874908
HistoryJun 01, 2024 - 12:00 a.m.

App can continue to fill input fields in the device even if user has not selected it as default Autofill service app.

2024-06-0100:00:00
Google
osv.dev
5
autofill
input validation
privilege escalation
user interaction

7 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill service settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

7 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%