In resetSettingsLocked of SettingsProvider.java, there is...
High severity
Unreviewed
Published
Oct 27, 2023
to the GitHub Advisory Database
•
Updated Apr 29, 2025
Description
Published by the National Vulnerability Database
Oct 27, 2023
Published to the GitHub Advisory Database
Oct 27, 2023
Last updated
Apr 29, 2025
In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References