PT-2023-7530 · Google · Android

Tchebb

·

Published

2023-12-01

·

Updated

2024-02-13

·

CVE-2023-45779

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to 2023-12-05 security patch
Description The issue is related to the APEX module framework of AOSP, where improperly used crypto could lead to a malicious update of platform components. This could result in local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation. Several Android OEMs, including ASUS, Fairphone, Lenovo, Microsoft, Nokia, Nothing, and Vivo, were affected as they were signing some of their APEX modules with publicly available test keys.
Recommendations For Android versions prior to 2023-12-05 security patch, update to a version that includes the December 2023 security update to resolve the issue. As a temporary workaround, consider restricting access to the APEX module framework until a patch is available.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2023-08584
CVE-2023-45779

Affected Products

Android