Lucene search

K
cvelistGoogle_androidCVELIST:CVE-2023-21251
HistoryJul 12, 2023 - 11:32 p.m.

CVE-2023-21251

2023-07-1223:32:23
google_android
www.cve.org
improper input validation
confirmdialog
oncreate
vpn connection bypass
user execution privileges
local escalation of privilege
user interaction

0.0004 Low

EPSS

Percentile

5.1%

In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user’s consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Android",
    "vendor": "Google",
    "versions": [
      {
        "status": "affected",
        "version": "13"
      },
      {
        "status": "affected",
        "version": "12L"
      },
      {
        "status": "affected",
        "version": "12"
      },
      {
        "status": "affected",
        "version": "11"
      }
    ]
  }
]

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2023-21251