ASB-A-238298970 PUBLISHED

In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Products

VendorProductVersions
platformpackages/apps/Settings13-next, 11:0, 11

Timeline

References

Open in Interactive Console →