In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
History

Fri, 16 Aug 2024 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published: 2024-02-15T22:31:15.329Z

Updated: 2024-08-16T15:32:15.092Z

Reserved: 2023-08-09T02:29:31.021Z

Link: CVE-2023-40109

cve-icon Vulnrichment

Updated: 2024-08-02T18:24:55.596Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-15T23:15:08.260

Modified: 2024-08-16T16:35:00.740

Link: CVE-2023-40109

cve-icon Redhat

No data.