Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In onCreate of CertInstaller.java, there is a possible way to overlay the Certificate Installation dialog by a malicious application. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139017101
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Android 安全漏洞
Vulnerability Description
Android是美国谷歌(Google)和开放手持设备联盟(简称OHA)的一套以Linux为基础的开源操作系统。 Android中的CertInstaller.java文件的‘onCreate’函数存在安全漏洞。攻击者可借助恶意的应用程序利用该漏洞覆盖证书安装的对话,获取提升的权限。以下产品及版本受到影响:Android 8.0版本,8.1版本,9版本,10版本。
CVSS Information
N/A
Vulnerability Type
N/A