In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-125 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2024-02-15T22:31:16.353Z
Updated: 2024-11-04T16:17:33.093Z
Reserved: 2023-08-09T02:29:33.868Z
Link: CVE-2023-40124
Vulnrichment
Updated: 2024-08-02T18:24:55.334Z
NVD
Status : Awaiting Analysis
Published: 2024-02-15T23:15:08.743
Modified: 2024-11-04T17:35:03.337
Link: CVE-2023-40124
Redhat
No data.