CVE-2023-21086
published 2023-04-19CVE-2023-21086: In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.5th percentile
In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-238298970
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_apps_settings | >= 11:0 < 11:2023-04-01 | 11:2023-04-01 |
| platform | packages_apps_settings | >= 12:0 < 12:2023-04-01 | 12:2023-04-01 |
| platform | packages_apps_settings | >= 12L:0 < 12L:2023-04-01 | 12L:2023-04-01 |
| platform | packages_apps_settings | >= 13-next:0 < 13-next:2023-04-01 | 13-next:2023-04-01 |
| platform | packages_apps_settings | >= 13:0 < 13:2023-04-01 | 13:2023-04-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2023-21086: Android Security Bulletin 2023-04-01
CVE: CVE-2023-21086
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-238298970
vendor_android·2023-04-01·CVSS 7.8
CVE-2023-21086 [HIGH] CVE-2023-21086: Android Security Bulletin 2023-04-01
CVE: CVE-2023-21086
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-238298970
Android Security Bulletin 2023-04-01
CVE: CVE-2023-21086
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-238298970
GHSA
GHSA-mmrr-rw97-7mcv: In isToggleable of SecureNfcEnabler
ghsa_unreviewed·2023-04-19
CVE-2023-21086 [HIGH] GHSA-mmrr-rw97-7mcv: In isToggleable of SecureNfcEnabler
In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-238298970
OSV
CVE-2023-21086: In isToggleable of SecureNfcEnabler
osv·2023-04-01
CVE-2023-21086 CVE-2023-21086: In isToggleable of SecureNfcEnabler
In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-19
Published