Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-35667
HistorySep 11, 2023 - 9:15 p.m.

Code injection

2023-09-1121:15:00
PRIOn knowledge base
www.prio-n.com
7
code injection
logic error
privilege escalation
user interaction

0.0004 Low

EPSS

Percentile

5.1%

In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CPENameOperatorVersion
androideq11.0
androideq12.0
androideq12.1
androideq13.0

0.0004 Low

EPSS

Percentile

5.1%

Related for PRION:CVE-2023-35667