Android NlpService Information Disclosure Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability in the NlpService component of Android allows for unauthorized access to location information due to a lack of proper permission checks. This flaw could be exploited to escalate privileges locally, without requiring additional execution rights or user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized access to location data and allow for local privilege escalation.

Remediation

Users can update their devices to the June 2018 security patch level to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.7
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.