PT-2023-18035 · Google · Android

Publicado

2023-07-01

·

Atualizado

2023-07-25

·

CVE-2023-21249

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions prior to the fixed version
Description The issue is related to a permissions bypass in multiple functions of OneTimePermissionUserManager.java. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android versions prior to the fixed version, consider restricting the use of the vulnerable OneTimePermissionUserManager.java functions until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Preservation of Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ASB-A-217981062
CVE-2023-21249

Produtos afetados

Android