Possible Security Bypass in NetworkManagementService.java

CVE-2017-13314
Currently unrated 🤨

Key Information

Vendor
Google
Status
Android
Vendor
CVE Published:
15 November 2024

Summary

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are supposed to be restricted to the VPN networks, with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Version(s)

Android = 7

Android = 8

Android = 8.1

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.