In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-216117246
References
Configurations
History
28 Jun 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
28 Mar 2023, 20:35
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* | |
References | (MISC) https://source.android.com/security/bulletin/pixel/2023-03-01 - Vendor Advisory | |
CWE | CWE-20 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
24 Mar 2023, 20:38
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-24 20:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-20976
Mitre link : CVE-2023-20976
CVE.ORG link : CVE-2023-20976
JSON object : View
Products Affected
- android
CWE
CWE-20
Improper Input Validation