Improper access control in Google Android - CVE-2016-6769
Published: January 12, 2017 / Updated: August 9, 2020
Google Android
Detailed vulnerability description
The vulnerability allows a local non-authenticated attacker to manipulate data.
An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access Smart Lock settings without a PIN. This issue is rated as Moderate because it first requires physical access to an unlocked device where Smart Lock was the last settings pane accessed by the user. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1. Android ID: A-29055171.