VDB

CESS-2023-21319

CESS-2023-21319 PUBLISHED CVSS 5.5 MEDIUM

In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Timeline

  • Oct 30, 2023 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›