In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published: 2024-03-11T18:55:39.493Z

Updated: 2024-08-05T17:35:27.703Z

Reserved: 2024-02-21T15:33:37.136Z

Link: CVE-2024-27222

cve-icon Vulnrichment

Updated: 2024-08-02T00:27:59.919Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-11T19:15:48.560

Modified: 2024-08-05T18:35:10.287

Link: CVE-2024-27222

cve-icon Redhat

No data.