In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
History

Thu, 03 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
CPEs cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
Vendors & Products Google
Google android

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2024-08-05T17:35:27.703Z

Reserved: 2024-02-21T15:33:37.136Z

Link: CVE-2024-27222

cve-icon Vulnrichment

Updated: 2024-08-02T00:27:59.919Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-11T19:15:48.560

Modified: 2025-04-03T15:55:03.310

Link: CVE-2024-27222

cve-icon Redhat

No data.