Android vulnerability

In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Published 2 Mar 2026Updated 8 Sep 20261 sources
CVSS 8.4

Source timeline

CVE record published by NVDView source ↗