VDB

GSD-2023-20932

GSD-2023-20932 PUBLISHED CVSS 3.299999952316284 LOW

In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-248251018

Risk Scores

CVSS v3.1
3.299999952316284
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
n/aAndroidAndroid-10 Android-11 Android-12 Android-12L Android-13

Timeline

  • Aug 29, 2022 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›