CVE-2023-21251Improper Input Validation in Frameworks Base

Severity
7.3HIGHNVD
EPSS
0.0%
top 99.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 13

Description

In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages4 packages

Androidplatform/frameworks_base13-next:013-next:2023-07-01+4
CVEListV5google/android4 versions+3
NVDgoogle/android4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8pqq-r364-7g26: In onCreate of ConfirmDialog2023-07-13
OSV
CVE-2023-21251: In onCreate of ConfirmDialog2023-07-01

📋Vendor Advisories

1
Android
CVE-2023-21251: Android Security Bulletin 2023-07-01 CVE: CVE-2023-21251 Severity: HIGH Type: EoP Affected AOSP versions: 11, 12, 12L, 13 References: A-2045546362023-07-01