CVE-2014-8609: Google Android

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component, action, or category information via a third-party authenticator in a crafted application, aka Bug 17356824.

Affected products

  • Google Android: up to and including 4.4.4; version 4.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; …

Published 2014-12-15. Last modified 2026-06-17.