cbcvebase.
CVE-2023-21133
published 2023-08-14

CVE-2023-21133: In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead…

medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

11 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformpackages_modules_permission>= 12:0 < 12:2023-08-0112:2023-08-01
platformpackages_modules_permission>= 12L:0 < 12L:2023-08-0112L:2023-08-01
platformpackages_modules_permission>= 13-next:0 < 13-next:2023-08-0113-next:2023-08-01
platformpackages_modules_permission>= 13:0 < 13:2023-08-0113:2023-08-01