Description
In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 25 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
ssvc
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 15 Aug 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 15 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In updatePermissionTreeSourcePackage of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-225880325 | In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2025-02-25T16:02:36.062Z
Reserved: 2022-11-03T00:00:00.000Z
Link: CVE-2023-20971
Updated: 2024-08-02T09:21:33.848Z
Status : Modified
Published: 2023-03-24T20:15:10.913
Modified: 2025-02-25T16:15:34.683
Link: CVE-2023-20971
No data.
OpenCVE Enrichment
No data.
Weaknesses