CVE-2023-21251
Summary
| CVE | CVE-2023-21251 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-13 00:15:00 UTC |
| Updated | 2023-07-25 14:48:00 UTC |
| Description | In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Android Security Bulletin—July 2023 | Android Open Source Project | MISC | source.android.com | |
| 57946e2bb73850e817b3c01fa5350d705e178e39 - platform/frameworks/base - Git at Google | MISC | android.googlesource.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.