VDB

CVE-2023-44129

CVE-2023-44129 PUBLISHED CVSS 3.5999999046325684 LOW

The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this functionality by launching this activity and then sending a broadcast with the "com.lge.message.action.QCLIP" action. The attacker can send, e.g., their own data/clipdata and set Intent.FLAG_GRANT_* flags. After the attacker received that intent in the "onActivityResult()" method, they would have access to arbitrary content providers that have the `android:grantUriPermissions="true"` flag set.

EPSS 0.09% · 0.7th percentile

Risk Scores

CVSS 3.1
3.5999999046325684
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
EPSS Score
0.09%
0.7th percentile

Affected Products

VendorProductVersions
googleandroid12.0
LG ElectronicsLG V60 Thin Q 5G(LMV600VM)Android 12

Timeline

  • Sep 27, 2023 CVE Published
  • Sep 28, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score
  • Dec 1, 2023 EPSS Score
  • Jan 2, 2024 EPSS Score
  • Feb 3, 2024 EPSS Score
  • Mar 6, 2024 EPSS Score
  • Apr 7, 2024 EPSS Score
  • May 9, 2024 EPSS Score
  • Jun 9, 2024 EPSS Score
  • Jul 11, 2024 EPSS Score
  • Aug 12, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›