ID |
CVE-2021-0952
|
Sažetak |
In doCropPhoto of PhotoSelectionHandler.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure of user's contacts with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-195748381 |
Reference |
|
CVSS |
Base: | 4.7 |
Impact: | 6.9 |
Exploitability: | 3.4 |
|
Pristup |
Vektor | Složenost | Autentikacija |
LOCAL |
MEDIUM |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
COMPLETE |
NONE |
NONE |
|
CVSS vektor |
AV:L/AC:M/Au:N/C:C/I:N/A:N |
Zadnje važnije ažuriranje |
17-12-2021 - 16:23 |
Objavljeno |
15-12-2021 - 19:15 |