ASB-A-179725730 PUBLISHED CVSS 6.900000095367432 MEDIUM

In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

Risk Scores

CVSS v4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
platformpackages/apps/Settings12:0, 12L:0, 12L
platformframeworks/base11:0, 11, 12:0

Timeline

References

Open in Interactive Console →