Loading HuntDB...

GHSA-vrvp-9jr4-5gp9

GitHub Security Advisory

⚠ Unreviewed LOW Has CVE

Advisory Details

he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete file method. An attacker can control conditions so this security check is never performed and an attacker-controlled file is deleted.

Related CVEs

Key Information

GHSA ID
GHSA-vrvp-9jr4-5gp9
Published
September 27, 2023 3:30 PM
Last Modified
April 4, 2024 7:55 AM
CVSS Score
2.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 9, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.