HIGH
In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation
Published Aug 14, 2023
7.8
HIGHCVSS 3.1
EPSS 0.18%
Description
In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected products
-
Affected
- 11
- 12
- 12L
-
Affected
- 11
- 12
- 12l
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://android.googlesource.com/platform/frameworks/base/+/4dea696369a309cf39daa3e94fec7156c290a9c2 Broken Link
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-25440 Advisory
- https://source.android.com/security/bulletin/2023-08-01 PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://android.googlesource.com/platform/frameworks/base/+/4dea696369a309cf39daa3e94fec7156c290a9c2 | Broken Link | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-25440 | Advisory | |
| https://source.android.com/security/bulletin/2023-08-01 | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Aug 14, 2023
Updated Oct 9, 2024
Reserved Nov 3, 2022
Link CVE-2023-21272
CISA Vulnrichment
Updated Oct 9, 2024
Red Hat
No data
GitHub
No data