PT-2023-17719 · Google · Android

Publicado

2023-03-01

·

Atualizado

2023-03-29

·

CVE-2023-20929

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions prior to the fixed version
Description The issue allows for local information disclosure due to an unrestricted broadcast intent in the sendHalfSheetCancelBroadcast function of HalfSheetActivity.java. This could lead to the disclosure of nearby BT MAC addresses without requiring additional execution privileges or user interaction.
Recommendations For Android versions prior to the fixed version, consider restricting the broadcast intent in the sendHalfSheetCancelBroadcast function of HalfSheetActivity.java to prevent local information disclosure.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ASB-A-234442700
CVE-2023-20929

Produtos afetados

Android