In AppTimeSpentPresenter of AppTimeSpentPreference.kt, there is a possible way to hijack implicit intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
{ "types": [ "EoP" ], "spl": "2025-02-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/426cbd623dbd4b59c68fc321de6a82e3962ae0a5" ], "severity": "High" }
"https://storage.googleapis.com/android-osv/ASB-A-356117796.json"
{ "types": [ "EoP" ], "spl": "2025-02-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/88e05af1a45c5bc6fd3dfc193571e4d91274a3cd" ], "severity": "High" }
{ "types": [ "EoP" ], "spl": "2025-02-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/e401ea474357b9980066e7447bff6699298f3a20" ], "severity": "High" }