First published: Fri Jul 17 2009(Updated: )
Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2348 is classified as a vulnerability that allows local users to bypass important security permissions in Android 1.5.
CVE-2009-2348 affects Google Android version 1.5.
To mitigate CVE-2009-2348, consider upgrading to a newer version of Android that has addressed this vulnerability.
CVE-2009-2348 allows the bypassing of the Manifest.permission.CAMERA and Manifest.permission.RECORD_AUDIO permissions.
CVE-2009-2348 can be exploited by applications that do not make explicit permission requests and run on Android 1.5.