High severity7.8NVD Advisory· Published Nov 19, 2024· Updated Jun 17, 2026
CVE-2017-13315
CVE-2017-13315
Description
In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:7.1.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:7.1.2:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*
- (no CPE)range: 6
Patches
Vulnerability mechanics
References
1- source.android.com/security/bulletin/2018-05-01nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.