CVE-2019-2023
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 0.5%
from disclosure to weapon0 days
Published on NVDJun 19
1st PoCMar 6
exploitation probability
0.5%top 58% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could allow an app to add or replace a HAL service with its own service, gaining code execution in a privileged process.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-121035042Upstream kernel
Affected products
n/a · Androidpublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46504⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.