An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
No PoCs from references.
- https://github.com/Aucode-n/AndroidSec
- https://github.com/iamsarvagyaa/AndroidSecNotes