VYPR

DreamPickerReceiver.kt

by Google

CVEs (1)

  • CVE-2026-57042MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.