PT-2023-17709 · Google · Android

Published

2023-01-01

·

Updated

2023-02-01

·

CVE-2023-20919

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description A logic error in the code of Settings.java could prevent package uninstallation, potentially leading to local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android version Android-13, apply the fix for the logic error in Settings.java to prevent package uninstallation issues and potential privilege escalation.

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

ASB-A-252663068
CVE-2023-20919

Affected Products

Android