PT-2023-22402 · Twilight · Twilight

Published

2023-06-09

·

Updated

2025-01-06

·

CVE-2023-29755

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Twilight version 13.3
Description The issue allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files. This can lead to unauthorized access and control.
Recommendations For Twilight version 13.3, consider restricting access to the SharedPreference files until a patch is available. As a temporary workaround, review and limit the permissions of installed apps to minimize the risk of exploitation.

Exploit

Fix

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2023-29755

Affected Products

Twilight