VDB
ASB-A-246301995
ASB-A-246301995
PUBLISHED
In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| platform | packages/providers/MediaProvider | 13:0, 13, 13:0 |
Timeline
- Jan 1, 2023 CVE Published
- May 15, 2026 CVE Updated