Android vulnerability

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Published 15 Sep 2026Updated 17 Sep 20261 sources
CVSS 6.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.