CVE-2009-2348
Android 1.5 CRBxx - Unauthenticated Permission Bypass via Camera and Microphone Access
Title source: llmDescription
Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.
References (8)
Core 8
Core References
Patch x_refsource_confirm
http://android.git.kernel.org/?p=platform/packages/apps/Camera.git%3Ba=commit%3Bh=e655d54160e5a56d4909f2459eeae9012e9f187f
Patch x_refsource_confirm
http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=7b7225c8fdbead25235c74811b30ff4ee690dc58
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51798
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/505012/100/0/threaded
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/07/16/4
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/35717
Patch x_refsource_confirm
http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=4d8adefd35efdea849611b8b02d61f9517e47760
Various Sources x_refsource_misc
http://www.ocert.org/advisories/ocert-2009-011.html
Scores
EPSS
0.0036
EPSS Percentile
28.0%
Details
CWE
CWE-94
Status
published
Products (1)
google/android
1.5
Published
Jul 17, 2009
Tracked Since
Feb 18, 2026