Android vulnerability

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Published 15 Sep 2026Updated 17 Sep 20261 sources
CVSS 6.7

Source timeline

CVE record published by NVDView source ↗