In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://source.android.com/security/bulletin/2017-06-01 | vendor advisory |
http://www.securityfocus.com/bid/98874 | vdb entry third party advisory |
http://www.securitytracker.com/id/1038623 | vdb entry |