Security: microg/GmsCore
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Work-account authenticator mints OAuth tokens for any caller, any scope, without consentGHSA-qqqw-h762-w2hw published
Sep 29, 2026 by mar-v-inHigh -
SafetyNet attest / verifyWithRecaptcha trusts the caller-supplied package nameGHSA-phcc-cx4h-vmq3 published
Sep 29, 2026 by mar-v-inLow -
Exported LocationManagerService accepts spoofed network locationsGHSA-frxh-v6rf-xfg4 published
Sep 29, 2026 by mar-v-inModerate -
CheckinService callback intent can start internal or privileged servicesGHSA-wrpf-76x8-cmh6 published
Sep 29, 2026 by mar-v-inModerate -
AskPermissionActivity is exported and lets the caller control the consent UIGHSA-rp4p-8x89-jhv5 published
Sep 29, 2026 by mar-v-inModerate -
AssistedSignInActivity trusts a caller-supplied package nameGHSA-hgxr-rxcr-m6vf published
Sep 29, 2026 by mar-v-inModerate -
Forged location-request "cache" injection into the exported LocationManagerServiceGHSA-29m7-f2vx-8cqq published
Sep 29, 2026 by mar-v-inModerate -
AssetModuleService allows for path traversal in module name and slice idGHSA-j946-qrvr-m286 published
Sep 29, 2026 by mar-v-inLow -
GServicesProvider is exported with no permission requirements or checksGHSA-h23g-4pvv-5hw9 published
Sep 29, 2026 by mar-v-inLow -
Block Store data isolation is bypassable via package-name prefix matchingGHSA-gxx5-cwvx-xch5 published
Sep 29, 2026 by mar-v-inHigh
Learn more about advisories related to microg/GmsCore in the GitHub Advisory Database