Lucene search

K
cvelistGoogle_androidCVELIST:CVE-2023-35676
HistorySep 11, 2023 - 8:09 p.m.

CVE-2023-35676

2023-09-1120:09:53
google_android
www.cve.org
4
cve-2023-35676
local escalation
unsafe pendingintent

EPSS

0

Percentile

5.1%

In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CNA Affected

[
  {
    "vendor": "Google",
    "product": "Android",
    "versions": [
      {
        "version": "13",
        "status": "affected"
      },
      {
        "version": "12L",
        "status": "affected"
      },
      {
        "version": "12",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

EPSS

0

Percentile

5.1%

Related for CVELIST:CVE-2023-35676