VDB

CISA-2023-40123

CISA-2023-40123 PUBLISHED

Reported by google_android · Published October 27, 2023

In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Products

VendorProductVersions
GoogleAndroid13, 12L, 12
GoogleAndroid13, 12L, 11

Timeline

  • Oct 27, 2023 CVE Published
  • Sep 9, 2024 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›