In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-862 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2024-02-15T22:31:14.906Z
Updated: 2024-10-31T17:09:33.100Z
Reserved: 2023-08-09T02:29:31.021Z
Link: CVE-2023-40105
Vulnrichment
Updated: 2024-08-02T18:24:55.562Z
NVD
Status : Awaiting Analysis
Published: 2024-02-15T23:15:08.083
Modified: 2024-10-31T17:35:01.983
Link: CVE-2023-40105
Redhat
No data.