In onSetRuntimePermissionGrantStateByDeviceAdmin of...
Moderate severity
Unreviewed
Published
May 16, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
May 15, 2023
Published to the GitHub Advisory Database
May 16, 2023
Last updated
Apr 4, 2024
In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-189942529
References