providers/settings/SettingsProvider.java in Android 7.0 before 2016-09-01 does not properly enforce the DISALLOW_CONFIG_VPN setting, which allows attackers to bypass an intended always-on VPN state via a crafted application, aka internal bug 29899712.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://android.googlesource.com/platform/frameworks/base/+/335702d106797bce8a88044783fa1fc1d5f751d0 | patch issue tracking |
http://source.android.com/security/bulletin/2016-09-01.html | vendor advisory |
http://www.securitytracker.com/id/1036763 | vdb entry |
http://www.securityfocus.com/bid/92872 | vdb entry |