CVE-2023-21233Use of Uninitialized Resource in Google Android

Severity
7.5HIGHNVD
EPSS
0.1%
top 66.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 14
Latest updateAug 15

Description

In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5google/android11
NVDgoogle/android11.0

🔴Vulnerability Details

1
GHSA
GHSA-mjp4-7v4x-pfcc: In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data2023-08-15