Android Intent Resolver ChooserActivity Elevation of Privilege Vulnerability

Vulnerability

A vulnerability in the ChooserActivity component of the Android Intent Resolver module allows for a local elevation of privilege. This issue arises from a missing permission check, which creates a potential bypass of factory reset protections. Exploitation of this vulnerability does not require any additional execution privileges or user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized access to elevated privileges, allowing a user to perform actions or access resources that are normally restricted.

Reproduction

To reproduce this vulnerability, first trigger factory reset protection on the device. Then, use an ADB command to initiate sharing via the ChooserActivity. The missing permission check will allow the sharing to bypass the factory reset protections, exploiting the elevation of privilege vulnerability.

Remediation

Users can update their devices to the October 2024 security patch level to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.7
remediation
0.0
relevance
0.0
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.