CVE | CVE-2023-20932 |
CVE Title | |
Published Date | 2023-02-28T17:15Z |
Modified Date | 2023-03-06T19:44Z |
CWE Type | CWE-20 |
CVSS 3.x | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Description | In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-248251018 |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://source.android.com/security/bulletin/2023-02-01 |
Reference Description | MISC https://source.android.com/security/bulletin/2023-02-01 |
Reference Description | |
Tags | Patch Vendor Advisory |
Sources | NIST MITRE |