PT-2023-17704 · Google · Android
CVE-2023-20914
·
Publicado
2023-05-01
·
Atualizado
2025-01-24
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions Android-11
Description
In the
onSetRuntimePermissionGrantStateByDeviceAdmin function of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Recommendations
For Android version Android-11, consider restricting access to sensitive information such as SMS messages to prevent local information disclosure until a patch is available. As a temporary workaround, review and restrict the use of the
onSetRuntimePermissionGrantStateByDeviceAdmin function in AdminRestrictedPermissionsUtils.java to minimize the risk of exploitation.Correção
Cleartext Storage of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Android