CVE-2013-6124
The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary file via an attack on the sensor-settings file.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0003 (0.0%)
Percentile: 9.0%
EPSS: 2026-05-06
Affects
codeaurora:android-msmTechnical description
The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary file via an attack on the sensor-settings file.
Published: 8/31/2014, 10:55:03 AM
Last modified: 5/6/2026, 10:30:45 PM