Description
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as call states, durations, called numbers, contacts info, etc.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-48485 | The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as call states, durations, called numbers, contacts info, etc. |
References
| Link | Providers |
|---|---|
| https://lgsecurity.lge.com/bulletins/mobile#updateDetails |
|
History
Fri, 20 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: LGE
Published:
Updated: 2024-09-20T19:47:59.285Z
Reserved: 2023-09-26T05:57:13.719Z
Link: CVE-2023-44126
Updated: 2024-08-02T19:59:50.988Z
Status : Modified
Published: 2023-09-27T15:19:36.647
Modified: 2024-11-21T08:25:17.973
Link: CVE-2023-44126
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD