VDB
GSD-2023-21231
GSD-2023-21231
PUBLISHED
In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-exported or permission-protected activity due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 13 |
Timeline
- Aug 7, 2023 CVE Published
- Apr 13, 2025 PoC Published