CVE-2019-9464 Information
Feb 14, 2021
cve
Description
In various functions of RecentLocationApps.java DevicePolicyManagerService.java and RecognitionService.java there is an incorrect warning indicating an app accessed the user’s location. This could dissolve the trust in the platform’s permission system with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141028068
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Reference
https://source.android.com/security/bulletin/2019-12-01
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
5.5
Share on: