Android KeyStore Permission Bypass

Discussion in 'News Aggregator' started by Packet Storm, 7 Feb 2018.

  1. Packet Storm

    Packet Storm Guest

    The keystore binder service ("android.security.IKeystoreService") allows users to issue several commands related to key management, including adding, removing, exporting and generating cryptographic keys. The service is accessible to many SELinux contexts, including application contexts, but also unprivileged daemons such as "media.codec". A permission bypass vulnerability exists in the KeyStore service due to getpidcon.

    Continue reading...
     

Share This Page

Loading...