← Back

CVE-2017-13227

nvd nist
Published: Nov 14, 2024Modified: Nov 20, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could lead to information disclosure with no additional execution privileges needed.  User interaction is not needed for exploitation.

Affected (2)

Products: Google: Android
1 product
Android
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 8.0
Version 8.1

References (1)

Source: security@android.com
PatchVendor Advisory

Timeline

No history available yet.