In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
History

Wed, 06 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-273
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published: 2023-07-12T23:29:44.442Z

Updated: 2024-11-06T18:03:47.682Z

Reserved: 2022-11-03T22:37:50.652Z

Link: CVE-2023-21246

cve-icon Vulnrichment

Updated: 2024-08-02T09:28:26.137Z

cve-icon NVD

Status : Modified

Published: 2023-07-13T00:15:23.727

Modified: 2024-11-21T07:42:29.117

Link: CVE-2023-21246

cve-icon Redhat

No data.