CVE-2023-20976

In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-216117246
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

28 Jun 2023, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://source.android.com/security/bulletin/pixel/2023-03-01', 'name': 'https://source.android.com/security/bulletin/pixel/2023-03-01', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) https://source.android.com/security/bulletin/pixel/2023-06-01 -

28 Mar 2023, 20:35

Type Values Removed Values Added
CPE cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
References (MISC) https://source.android.com/security/bulletin/pixel/2023-03-01 - (MISC) https://source.android.com/security/bulletin/pixel/2023-03-01 - Vendor Advisory
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

24 Mar 2023, 20:38

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-24 20:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-20976

Mitre link : CVE-2023-20976

CVE.ORG link : CVE-2023-20976


JSON object : View

Products Affected

google

  • android
CWE
CWE-20

Improper Input Validation