PT-2023-27279 · Google · Android
Published
2023-10-01
·
Updated
2023-10-30
·
CVE-2023-40125
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions prior to the fixed version
Description
A permission bypass issue in the ApnEditor.java file allows a Guest user to change the APN, potentially leading to local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations
For Android versions prior to the fixed version, consider restricting access to the ApnEditor.java file to prevent unauthorized changes to the APN settings.
As a temporary workaround, consider disabling the
onCreate method in ApnEditor.java until a patch is available.
Avoid using the APN settings modification feature until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android