PT-2019-19489 · Google · Android

Published

2019-09-27

·

Updated

2020-08-24

·

CVE-2019-9269

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-10
Description In System Settings, there is a possible permissions bypass due to a cached Linux user ID. This could lead to a local permissions bypass with no additional execution privileges needed. User interaction is needed for exploitation.
Recommendations For Android version Android-10, update the system to remove the cached Linux user ID and prevent permissions bypass.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9269

Affected Products

Android