PT-2023-17719 · Google · Android

Published

2023-03-01

·

Updated

2023-03-29

·

CVE-2023-20929

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions prior to the fixed version
Description The issue allows for local information disclosure due to an unrestricted broadcast intent in the sendHalfSheetCancelBroadcast function of HalfSheetActivity.java. This could lead to the disclosure of nearby BT MAC addresses without requiring additional execution privileges or user interaction.
Recommendations For Android versions prior to the fixed version, consider restricting the broadcast intent in the sendHalfSheetCancelBroadcast function of HalfSheetActivity.java to prevent local information disclosure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ASB-A-234442700
CVE-2023-20929

Affected Products

Android