We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-21113



Assignergoogle_android
Reserved2022-11-03
Published2024-07-09
Updated2024-08-02

Description

In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Problem types

Elevation of privilege

Product status

Default status
unaffected

13
affected

12L
affected

12
affected

References

https://android.googlesource.com/platform/build/soong/+/e7b7f0833dc47ade981eddfbf462dcc143dddd10

https://android.googlesource.com/platform/frameworks/base/+/17dd11248a66b2722aa3ef07701b7f09a64160e5

https://android.googlesource.com/platform/prebuilts/module_sdk/Wifi/+/c705bae1a4d50bd7b4f8cc919097d1aae568dd22

https://source.android.com/security/bulletin/2024-06-01

cve.org CVE-2023-21113

nvd.nist.gov CVE-2023-21113

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.