PT-2023-17714 · Google · Android Kernel

Published

2023-01-24

·

Updated

2023-02-01

·

CVE-2023-20923

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue allows access to protected content providers due to a permissions bypass in exported content providers of ShannonRcs. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations For Android kernel, consider restricting access to sensitive content providers to minimize the risk of information disclosure until a patch is available.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-20923

Affected Products

Android Kernel