Permissions, Privileges, and Access Controls in Google Android - CVE-2019-1994

 

Permissions, Privileges, and Access Controls in Google Android - CVE-2019-1994

Published: February 28, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36090
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1994
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could lead to unwanted access to development settings, with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-117770924.


Affected software

Google Android

How to mitigate CVE-2019-1994

Install update from vendor's website.


External References

Related Security Bulletins