PT-2023-27279 · Google · Android

Published

2023-10-01

·

Updated

2023-10-30

·

CVE-2023-40125

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to the fixed version
Description A permission bypass issue in the ApnEditor.java file allows a Guest user to change the APN, potentially leading to local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android versions prior to the fixed version, consider restricting access to the ApnEditor.java file to prevent unauthorized changes to the APN settings. As a temporary workaround, consider disabling the onCreate method in ApnEditor.java until a patch is available. Avoid using the APN settings modification feature until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ASB-A-279902472
CVE-2023-40125

Affected Products

Android