Security Advisory

CVE-2024-27222

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-03-11 18:55:39
Last updated 2024-08-05 17:35:27
Assigner Google_Devices
State PUBLISHED

Description

In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.