CVE Vulnerabilities

CVE-2023-20904

Published: Jan 26, 2023 | Modified: Feb 01, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-246300272

Affected Software

Name Vendor Start Version End Version
Android Google 12.1 (including) 12.1 (including)
Android Google 13.0 (including) 13.0 (including)

References