Lucene search

K
cvelistGoogle_androidCVELIST:CVE-2023-20932
HistoryFeb 28, 2023 - 12:00 a.m.

CVE-2023-20932

2023-02-2800:00:00
google_android
www.cve.org
android
local info disclosure
input validation

3.8 Low

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-248251018

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Android",
    "versions": [
      {
        "version": "Android-10 Android-11 Android-12 Android-12L Android-13",
        "status": "affected"
      }
    ]
  }
]

3.8 Low

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2023-20932