ASB-A-119041698

Import Source
https://storage.googleapis.com/android-osv/ASB-A-119041698.json
Aliases
  • CVE-2019-2219
Published
2021-05-01T00:00:00Z
Modified
2024-04-26T14:41:14Z
Details

In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
11:0
Fixed
11:2021-05-05

Affected versions

Other

11

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/d96f50a85f7762f50f672981c194ebb9e6ce4ff6"
    ],
    "spl": "2021-05-05",
    "types": [
        "ID"
    ],
    "severity": "High"
}