CVE-2019-2219
published 2019-12-06CVE-2019-2219: In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to…
PriorityP420medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.15%
4.4th percentile
In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119041698
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 11:0 < 11:2021-05-05 | 11:2021-05-05 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2019-2219: Android Security Bulletin 2021-05-01
CVE: CVE-2019-2219
Severity: HIGH
Type: ID
Affected AOSP versions: 11
References: A-119041698
vendor_android·2021-05-01·CVSS 4.7
CVE-2019-2219 [MEDIUM] CVE-2019-2219: Android Security Bulletin 2021-05-01
CVE: CVE-2019-2219
Severity: HIGH
Type: ID
Affected AOSP versions: 11
References: A-119041698
Android Security Bulletin 2021-05-01
CVE: CVE-2019-2219
Severity: HIGH
Type: ID
Affected AOSP versions: 11
References: A-119041698
GHSA
GHSA-vrpr-p6w2-crwx: In System UI, there is a possible bypass of user's consent for access to sensor data due to a race condition
ghsa_unreviewed·2022-05-24
CVE-2019-2219 [MEDIUM] CWE-362 GHSA-vrpr-p6w2-crwx: In System UI, there is a possible bypass of user's consent for access to sensor data due to a race condition
In System UI, there is a possible bypass of user's consent for access to sensor data due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-119041698
OSV
CVE-2019-2219: In several functions of NotificationManagerService
osv·2021-05-01
CVE-2019-2219 CVE-2019-2219: In several functions of NotificationManagerService
In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-06
Published