In onBindingDied of CallRedirectionProcessor.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.
References
| Link | Resource |
|---|---|
| https://android.googlesource.com/platform/packages/services/Telecomm/+/5b335401d1c8de7d1c85f4a0cf353f7f9fc30218 | Patch |
| https://source.android.com/security/bulletin/2023-10-01 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
30 Oct 2023, 17:14
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| References | (MISC) https://source.android.com/security/bulletin/2023-10-01 - Patch, Vendor Advisory | |
| References | (MISC) https://android.googlesource.com/platform/packages/services/Telecomm/+/5b335401d1c8de7d1c85f4a0cf353f7f9fc30218 - Patch | |
| First Time |
Google android
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| CPE | cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:* cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* |
27 Oct 2023, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-10-27 21:15
Updated : 2024-09-09 20:35
NVD link : CVE-2023-40130
Mitre link : CVE-2023-40130
JSON object : View
Products Affected
- android
CWE
