In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-216117246
References
Configurations
History
21 Nov 2024, 07:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://source.android.com/security/bulletin/pixel/2023-06-01 - |
28 Jun 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2023-03-24 20:15
Updated : 2024-11-21 07:41
NVD link : CVE-2023-20976
Mitre link : CVE-2023-20976
CVE.ORG link : CVE-2023-20976
JSON object : View
Products Affected
- android
CWE
CWE-20
Improper Input Validation