In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2023-10-27T20:22:56.553Z
Updated: 2024-08-02T18:24:55.284Z
Reserved: 2023-08-09T02:29:31.894Z
Link: CVE-2023-40120
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-10-27T21:15:08.667
Modified: 2024-11-21T08:18:48.910
Link: CVE-2023-40120
Redhat
No data.