First published: Mon Feb 04 2019(Updated: )
In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could lead to unwanted access to development settings, with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-117770924.
Credit: security@android.com security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =8.0 | |
Android | =8.1 | |
Android | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1994 has a moderate severity rating due to the potential for unauthorized access to development settings.
To fix CVE-2019-1994, it is recommended to update your Android device to the latest version that includes the security patch.
CVE-2019-1994 affects Android 8.0, 8.1, and 9.0.
Yes, user interaction is required to exploit CVE-2019-1994.
The implications of CVE-2019-1994 include the risk of leaving sensitive development settings accessible to unauthorized users.