The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive settings of the Android Client application itself.
The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.
Link | Tags |
---|---|
https://psirt.bosch.com/security-advisories/BOSCH-SA-175607.html | mitigation vendor advisory |