CVE-2017-13227: medium-severity vulnerability in Google Android
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.5epss 0.1%
exploitation probability
0.1%top 100% of all CVEs
observed exploitation
nono source reports it
In the autofill service, the package name that is provided by the app process is trusted inappropriately. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
Google · AndroidRelated CVEs — Google Android
In the same product, most dangerous first.