Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
LG ThinQ Service - Intent redirection with system privilege/LaunchAnyWhere
Vulnerability Description
The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a broadcast with the action "com.lge.lms.things.notification.ACTION". Additionally, this vulnerability is very dangerous because LG ThinQ Service is a system app (having android:sharedUserId="android.uid.system" setting). Intent redirection in this app leads to accessing arbitrary not exported activities of absolutely all apps.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L
Vulnerability Type
CWE-926
Vulnerability Title
LG mobile 安全漏洞
Vulnerability Description
LG mobile是韩国乐金(LG)公司的一系列移动设备产品。 LG mobile存在安全漏洞。攻击者利用该漏洞可以获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A