4.7
CVSSv2

CVE-2019-2219

Published: 06/12/2019 Updated: 21/06/2021
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 418
Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119041698

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 9.0

google android 10.0

Github Repositories

SimpleSpyware - Black HatEurope 2019 - Demo App This repo contains a demonstration spyware app The app shows how Androids foreground services can be used to collect user data More technical information can be found within the presentation slides Download The latest prebuilt apk can be downloaded from the releases page: APKs WhitePaper General Notes Please do not use or red