PT-2023-5280 · Google · Android

Published

2023-06-15

·

Updated

2024-09-26

·

CVE-2023-35671

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The issue is related to a logic error in the code of HostEmulationManager.java, specifically in the onHostEmulationData function. This error allows a general-purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode, leading to local information disclosure without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ASB-A-268038643
BDU:2023-05903
CVE-2023-35671

Affected Products

Android