In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is not needed for exploitation.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
google android 11.0 |
||
google android 12.0 |
||
google android 12.1 |
||
google android 13.0 |
||
google android 14.0 |