Improper access control in Nextcloud Android Talk - CVE-2022-41926
Published: November 28, 2022
Nextcloud Android Talk
Nextcloud
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the broadcast receiver. A remote attacker can bypass implemented security restrictions and cause interference on starting a call or requesting media permissions.