In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to a confused deputy. This could ...
In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limits causing resource exhaustion...
In multiple functions of BaseBundle.java, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local...
In connectInternal of MediaBrowser.java, there is a possible way to access while in use permission while the app is in background due to a logic error...
In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service due to res...
In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass. This could lead to local esc...
In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in the background due to FGS whil...
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalati...
In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation. This could lead t...
In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could lead to local es...
In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no addi...
In multiple functions of NotificationStation.java, there is a possible cross-profile information disclosure due to a confused deputy. This could lead ...
In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to modify secure settings due to a ...
In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated to a compani...
In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic error in the ...