Vulnerabilities > CVE-2019-9380 - Missing Authorization vulnerability in Google Android 10.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
In the settings UI, there is a possible spoofing vulnerability due to a missing permission check. This could lead to a user mistakenly changing permission settings with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-123700098
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 |