CVE-2023-35669

In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:08

Type Values Removed Values Added
References () https://android.googlesource.com/platform/frameworks/base/+/f810d81839af38ee121c446105ca67cb12992fc6 - Issue Tracking, Patch () https://android.googlesource.com/platform/frameworks/base/+/f810d81839af38ee121c446105ca67cb12992fc6 - Issue Tracking, Patch
References () https://source.android.com/security/bulletin/2023-09-01 - Vendor Advisory () https://source.android.com/security/bulletin/2023-09-01 - Vendor Advisory

14 Sep 2023, 01:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References (MISC) https://source.android.com/security/bulletin/2023-09-01 - (MISC) https://source.android.com/security/bulletin/2023-09-01 - Vendor Advisory
References (MISC) https://android.googlesource.com/platform/frameworks/base/+/f810d81839af38ee121c446105ca67cb12992fc6 - (MISC) https://android.googlesource.com/platform/frameworks/base/+/f810d81839af38ee121c446105ca67cb12992fc6 - Issue Tracking, Patch
CWE CWE-502
First Time Google android
Google
CPE cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

11 Sep 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-11 21:15

Updated : 2024-11-21 08:08


NVD link : CVE-2023-35669

Mitre link : CVE-2023-35669

CVE.ORG link : CVE-2023-35669


JSON object : View

Products Affected

google

  • android
CWE
CWE-502

Deserialization of Untrusted Data