Closed GoogleCodeExporter closed 8 years ago
Reported in AOSP as https://code.google.com/p/android/issues/detail?id=200617
Original comment by fors...@google.com
on 9 Feb 2016 at 12:44
Original comment by fors...@google.com
on 10 Feb 2016 at 10:00
The Android Security Team have assessed the impact of this issue and found that
it's not exploitable. Any vulnerable service either would not accept it's own
security context as valid or if it did the majority of use cases already have
access (such as untrusted_app to the keystore service). Therefore while there's
an elevation of privilege vulnerability in the ability to cause the service to
check the incorrect security context it's not exploitable in a default android
release. This is planned to be fixed in mainline AOSP, but won't be back ported
therefore marking it as wont fix.
As this bug has been derestricted on the AOSP issue tracker there's no reason
to keep it locked down here.
Original comment by fors...@google.com
on 19 Feb 2016 at 11:55
Original issue reported on code.google.com by
fors...@google.com
on 9 Feb 2016 at 12:41