CVE-2023-40076
published 2023-12-04CVE-2023-40076: In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead…
PriorityP431medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
2.28%
81.2th percentile
In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 14-next:0 < 14-next:2023-12-01 | 14-next:2023-12-01 |
| platform | frameworks_base | >= 14:0 < 14:2023-12-01 | 14:2023-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-79g5-39qj-ggvg: In createPendingIntent of CredentialManagerUi
ghsa_unreviewed·2023-12-05
CVE-2023-40076 [MEDIUM] CWE-276 GHSA-79g5-39qj-ggvg: In createPendingIntent of CredentialManagerUi
In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2023-40076: In createPendingIntent of CredentialManagerUi
osv·2023-12-01
CVE-2023-40076 CVE-2023-40076: In createPendingIntent of CredentialManagerUi
In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2023-40076: Android Security Bulletin 2023-12-01
CVE: CVE-2023-40076
Severity: CRITICAL
Type: ID
Affected AOSP versions: 14
References: A-303835719
vendor_android·2023-12-01·CVSS 5.5
CVE-2023-40076 [MEDIUM] CVE-2023-40076: Android Security Bulletin 2023-12-01
CVE: CVE-2023-40076
Severity: CRITICAL
Type: ID
Affected AOSP versions: 14
References: A-303835719
Android Security Bulletin 2023-12-01
CVE: CVE-2023-40076
Severity: CRITICAL
Type: ID
Affected AOSP versions: 14
References: A-303835719
No detection rules found.
No public exploits indexed.
Checkpoint
11th December – Threat Intelligence Report
blogs_checkpoint·2023-12-11
CVE-2023-40088 11th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th December, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The American Greater Richmond Transit Company (GRTC), which provides services for millions of people, has been a victim of cyber-attack that impacted certain applications and parts of the GRTC network. The Play ransomware gang claimed responsibility for the attack.
Check Point Harmony Endpoint and Threat Emulation prov
Bleepingcomputer
December Android updates fix critical zero-click RCE flaw
blogs_bleepingcomputer·2023-12-04·CVSS 8.4
CVE-2023-40088 [HIGH] December Android updates fix critical zero-click RCE flaw
## December Android updates fix critical zero-click RCE flaw
## Sergiu Gatlan
Google announced today that the December 2023 Android security updates tackle 85 vulnerabilities, including a critical severity zero-click remote code execution (RCE) bug.
Tracked as CVE-2023-40088, the zero-click RCE bug was found in Android's System component and doesn't require additional privileges to be exploited.
While the company has yet to reveal if attackers have targeted this security flaw in the wild, threat actors could exploit it to gain arbitrary code execution without user interaction.
"The most severe of these issues is a critical security vulnerability in the System component that could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User int
https://android.googlesource.com/platform/frameworks/base/+/9b68987df85b681f9362a3cadca6496796d23bbchttps://source.android.com/security/bulletin/2023-12-01https://android.googlesource.com/platform/frameworks/base/+/9b68987df85b681f9362a3cadca6496796d23bbchttps://source.android.com/security/bulletin/2023-12-01
2023-12-04
Published