PT-2025-35659 · Google · Framework

Published

2025-09-03

·

Updated

2025-09-08

·

CVE-2023-21466

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions framework versions prior to SMR Apr-2023 Release 1
Description A PendingIntent hijacking issue exists in CertificatePolicy within the framework. This allows local attackers to access a contentProvider without the necessary permissions.
Recommendations Update to SMR Apr-2023 Release 1 or later.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-21466

Affected Products

Framework