CVE-2019-2103

Publication date

2019-09-05 21:35:11

Family

google_android

State

PUBLISHED

Description

In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.