CVE-2014-8609
HIGH 7.2EPSS 0.6%
The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component, action, or category information via a third-party authenticator in a crafted application, aka Bug 17356824.
- CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 0.64% chance of exploitation in the next 30 days, 48th percentile
- Published
- 2014-12-15
- Updated
- 2024-08-06
Proof-of-concept exploits (4)
- MazX0p/CVE-2014-8609-POC0★ · 2021-07-17
- locisvv/Vulnerable-CVE-2014-86090★ · 2015-04-07
- ratiros01/CVE-2014-8609-exploit0★ · 2022-05-16
- retme7/broadAnyWhere_poc_by_retme_bug_1735682455★ · 2014-11-26