← Back to CVE List

CVE-2019-2218

Published: 2019-12-06T23:15Z
Last Modified: 2024-11-21T04:40Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check. This could lead to local escalation of privilege by installing malicious packages with User execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141169173 > MITRE Terms of Use apply – see LICENSE‑MITRE.txt