In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217699.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/43996/ | third party advisory vdb entry exploit |
https://source.android.com/security/bulletin/2018-02-01 | vendor advisory |
http://www.securityfocus.com/bid/102979 | third party advisory vdb entry |