CVE-2023-20914Cleartext Storage of Sensitive Info in Google Android

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 99.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 15
Latest updateMay 16

Description

In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-189942529

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Androidplatform/frameworks_base13-next:013-next:2023-05-01+1
CVEListV5google/androidAndroid-11
NVDgoogle/android11.0
Androidplatform/packages_modules_permission13-next:013-next:2023-05-01

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9mc5-9564-268j: In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils2023-05-16
CVEList
CVE-2023-20914: In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils2023-05-15
OSV
CVE-2023-20914: In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils2023-05-01

📋Vendor Advisories

1
Android
CVE-2023-20914: Android Security Bulletin 2023-05-01 CVE: CVE-2023-20914 Severity: HIGH Type: ID Affected AOSP versions: 11 References: A-1899425292023-05-01
CVE-2023-20914 — Cleartext Storage of Sensitive Info | cvebase