PT-2023-22402 · Twilight · Twilight

CVE-2023-29755

·

Publicado

2023-06-09

·

Atualizado

2025-01-06

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Twilight version 13.3
Description The issue allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files. This can lead to unauthorized access and control.
Recommendations For Twilight version 13.3, consider restricting access to the SharedPreference files until a patch is available. As a temporary workaround, review and limit the permissions of installed apps to minimize the risk of exploitation.

Exploit

Correção

Insecure Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-29755

Produtos afetados

Twilight