cbcvebase.
CVE-2023-21138
published 2023-06-15

CVE-2023-21138: In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.08%
0.3th percentile
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-273260090

Affected

11 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformpackages_services_telecomm>= 11:0 < 11:2023-06-0111:2023-06-01
platformpackages_services_telecomm>= 12:0 < 12:2023-06-0112:2023-06-01
platformpackages_services_telecomm>= 12L:0 < 12L:2023-06-0112L:2023-06-01
platformpackages_services_telecomm>= 13-next:0 < 13-next:2023-06-0113-next:2023-06-01
platformpackages_services_telecomm>= 13:0 < 13:2023-06-0113:2023-06-01
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.