CVE-2023-20976

In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-216117246
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:41

Type Values Removed Values Added
References () https://source.android.com/security/bulletin/pixel/2023-06-01 - () https://source.android.com/security/bulletin/pixel/2023-06-01 -

28 Jun 2023, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://source.android.com/security/bulletin/pixel/2023-03-01', 'name': 'https://source.android.com/security/bulletin/pixel/2023-03-01', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) https://source.android.com/security/bulletin/pixel/2023-06-01 -

Information

Published : 2023-03-24 20:15

Updated : 2024-11-21 07:41


NVD link : CVE-2023-20976

Mitre link : CVE-2023-20976

CVE.ORG link : CVE-2023-20976


JSON object : View

Products Affected

google

  • android
CWE
CWE-20

Improper Input Validation