Android Clipboard Listener Lock Screen Bypass Vulnerability Allowing Privilege Escalation
Vulnerability
A vulnerability in the ClipboardListener component of the Android framework has been identified, which allows for a partial bypass of the lock screen. This issue could lead to unauthorized access to certain functionalities, enabling local escalation of privileges without the need for additional execution rights. Notably, user interaction is not required for exploitation.
Impact
Exploitation of this vulnerability could result in unauthorized access to clipboard data and associated intents, potentially leading to unauthorized actions or access within the system.
Remediation
Users can update their devices to the December 2024 security patch level to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
