CVE-2019-2173: High severity Google Android vulnerability
In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-123013720
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2173?
CVE-2019-2173 has a high severity rating due to its potential for local privilege escalation.
How do I fix CVE-2019-2173?
To fix CVE-2019-2173, users should update their Android device to the latest available version to ensure the permission checks are properly enforced.
Which Android versions are affected by CVE-2019-2173?
CVE-2019-2173 affects Android versions 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
What is the impact of exploiting CVE-2019-2173?
Exploiting CVE-2019-2173 could lead to local escalation of privilege without requiring additional execution privileges.
Is user interaction required to exploit CVE-2019-2173?
No, user interaction is not needed for the exploitation of CVE-2019-2173.