In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
The product does not correctly convert an object, resource, or structure from one type to a different type.
Link | Tags |
---|---|
https://source.android.com/security/bulletin/2018-06-01 | patch vendor advisory |