In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258422365
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-25278 | In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258422365 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://source.android.com/security/bulletin/2023-05-01 |
|
History
Fri, 24 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2025-01-24T17:37:33.624Z
Reserved: 2022-11-03T00:00:00.000Z
Link: CVE-2023-21110
Updated: 2024-08-02T09:28:25.807Z
Status : Modified
Published: 2023-05-15T22:15:11.910
Modified: 2025-01-24T18:15:31.133
Link: CVE-2023-21110
No data.
OpenCVE Enrichment
No data.
EUVD