PT-2023-22375 · Google · Android
Published
2023-06-01
·
Updated
2025-01-09
·
CVE-2023-29723
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Glitter Unicorn Wallpaper app for Android versions 7.0 through 8.0
Description
The issue allows unauthorized applications to inject data into the database that stores user personal preferences, which can be loaded into memory and used when the application is opened. By injecting data, an attacker can force the application to load malicious image URLs and display them in the UI. As the amount of data increases, it will eventually cause the application to trigger an out-of-memory (OOM) error and crash, resulting in a persistent denial of service attack.
Recommendations
For Android versions 7.0 through 8.0, consider restricting access to the database that records user personal preferences to prevent unauthorized data injection until a patch is available. As a temporary workaround, avoid using the Glitter Unicorn Wallpaper app to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android