In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
References
Link | Resource |
---|---|
https://android.googlesource.com/platform/frameworks/base/+/57946e2bb73850e817b3c01fa5350d705e178e39 | Patch |
https://source.android.com/security/bulletin/2023-07-01 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
25 Jul 2023, 14:48
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 | |
CPE | cpe:2.3:o:google:android:13.1:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* |
|
References | (MISC) https://source.android.com/security/bulletin/2023-07-01 - Patch, Vendor Advisory | |
References | (MISC) https://android.googlesource.com/platform/frameworks/base/+/57946e2bb73850e817b3c01fa5350d705e178e39 - Patch | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
13 Jul 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-13 00:15
Updated : 2024-02-05 00:01
NVD link : CVE-2023-21251
Mitre link : CVE-2023-21251
CVE.ORG link : CVE-2023-21251
JSON object : View
Products Affected
- android
CWE
CWE-20
Improper Input Validation