Permissions, Privileges, and Access Controls in Google Android - CVE-2013-6271
Published: December 14, 2013 / Updated: August 10, 2020
Google Android
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the updateUnlockMethodAndFinish method in the com.android.settings.ChooseLockGeneric class with the PASSWORD_QUALITY_UNSPECIFIED option.