PT-2023-29117 · Lg · Com.Lge.Bluetoothsetting
Published
2023-09-27
·
Updated
2023-10-02
·
CVE-2023-44123
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
com.lge.bluetoothsetting (affected versions not specified)
Description
The issue is related to the use of implicit PendingIntents with the PendingIntent.FLAG MUTABLE set, which can lead to the theft and/or over-write of arbitrary files with system privilege in the Bluetooth app. An attacker's app, if it has access to app notifications, can intercept them and redirect them to its activity. This can result in the attacker's app being granted access permissions to content providers with the
android:grantUriPermissions="true" flag.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Com.Lge.Bluetoothsetting