CVE-2023-21035
published 2023-03-24CVE-2023-21035: In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same package name…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.11%
1.5th percentile
In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-184847040
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | packages_modules_permission | >= 13:0 < 13:2023-03-01 | 13:2023-03-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-52qh-2823-96fv: In multiple functions of BackupHelper
ghsa_unreviewed·2023-03-24
CVE-2023-21035 [HIGH] CWE-863 GHSA-52qh-2823-96fv: In multiple functions of BackupHelper
In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-184847040
OSV
CVE-2023-21035: In multiple functions of BackupHelper
osv·2023-03-24·CVSS 7.8
CVE-2023-21035 [HIGH] CVE-2023-21035: In multiple functions of BackupHelper
In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-184847040
OSV
CVE-2023-21035: In multiple functions of BackupHelper
osv·2023-03-01
CVE-2023-21035 CVE-2023-21035: In multiple functions of BackupHelper
In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-24
Published