CVE-2019-1994: Critical severity android vulnerability
In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could lead to unwanted access to development settings, with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-117770924.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1994?
CVE-2019-1994 has a moderate severity rating due to the potential for unauthorized access to development settings.
How do I fix CVE-2019-1994?
To fix CVE-2019-1994, it is recommended to update your Android device to the latest version that includes the security patch.
What versions of Android are affected by CVE-2019-1994?
CVE-2019-1994 affects Android 8.0, 8.1, and 9.0.
Is user interaction required to exploit CVE-2019-1994?
Yes, user interaction is required to exploit CVE-2019-1994.
What are the implications of CVE-2019-1994?
The implications of CVE-2019-1994 include the risk of leaving sensitive development settings accessible to unauthorized users.