Security Advisory

CVE-2021-23244

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-12-27 18:48:24
Last updated 2024-08-03 19:05:54
Assigner OPPO
State PUBLISHED

Description

ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelist is not installed, attacker can disguise app with the same package name to obtain dangerous permission.