Description
In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-25425 | In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
References
History
Wed, 06 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2024-11-06T14:49:25.431Z
Reserved: 2022-11-03T22:37:50.653Z
Link: CVE-2023-21257
Updated: 2024-08-02T09:28:26.135Z
Status : Modified
Published: 2023-07-13T00:15:24.143
Modified: 2024-11-21T07:42:30.423
Link: CVE-2023-21257
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD