Loading HuntDB...

GHSA-g3p7-6jrm-6c7q

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Related CVEs

Key Information

GHSA ID
GHSA-g3p7-6jrm-6c7q
Published
September 11, 2024 12:30 AM
Last Modified
November 4, 2024 9:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 24, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.