Lucene search

K
cveGoogle_androidCVE-2023-40124
HistoryFeb 15, 2024 - 11:15 p.m.

CVE-2023-40124

2024-02-1523:15:08
google_android
web.nvd.nist.gov
5443
cve-2023-40124
cross-user read
local information disclosure
nvd
confused deputy

AI Score

6

Confidence

Low

EPSS

0

Percentile

9.0%

In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected configurations

Vulners
Node
googleandroidMatch13
OR
googleandroidMatch13
OR
googleandroidMatch12l
OR
googleandroidMatch13
OR
googleandroidMatch12l
OR
googleandroidMatch12
OR
googleandroidMatch13
OR
googleandroidMatch12l
OR
googleandroidMatch12
OR
googleandroidMatch11
VendorProductVersionCPE
googleandroid13cpe:2.3:o:google:android:13:*:*:*:*:*:*:*
googleandroid12lcpe:2.3:o:google:android:12l:*:*:*:*:*:*:*
googleandroid12cpe:2.3:o:google:android:12:*:*:*:*:*:*:*
googleandroid11cpe:2.3:o:google:android:11:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Google",
    "product": "Android",
    "versions": [
      {
        "version": "13",
        "status": "affected"
      },
      {
        "version": "12L",
        "status": "affected"
      },
      {
        "version": "12",
        "status": "affected"
      },
      {
        "version": "11",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

6

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2023-40124