PT-2023-7530 · Google · Android
Tchebb
·
Published
2023-12-01
·
Updated
2024-02-13
·
CVE-2023-45779
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions prior to 2023-12-05 security patch
Description
The issue is related to the APEX module framework of AOSP, where improperly used crypto could lead to a malicious update of platform components. This could result in local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation. Several Android OEMs, including ASUS, Fairphone, Lenovo, Microsoft, Nokia, Nothing, and Vivo, were affected as they were signing some of their APEX modules with publicly available test keys.
Recommendations
For Android versions prior to 2023-12-05 security patch, update to a version that includes the December 2023 security update to resolve the issue. As a temporary workaround, consider restricting access to the APEX module framework until a patch is available.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android