CVE-2023-32808Google Android vulnerability

2 documents2 sources
Severity
4.4MEDIUMNVD
EPSS
0.0%
top 93.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 4

Description

In bluetooth driver, there is a possible read and write access to registers due to improper access control of register interface. This could lead to local leak of sensitive information with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07849751; Issue ID: ALPS07849751.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages1 packages

NVDgoogle/android13.0

🔴Vulnerability Details

1
GHSA
GHSA-p2wq-ggq4-chhc: In bluetooth driver, there is a possible read and write access to registers due to improper access control of register interface2023-09-04