PT-2023-17704 · Google · Android

CVE-2023-20914

·

Published

2023-05-01

·

Updated

2025-01-24

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-11
Description In the onSetRuntimePermissionGrantStateByDeviceAdmin function of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android version Android-11, consider restricting access to sensitive information such as SMS messages to prevent local information disclosure until a patch is available. As a temporary workaround, review and restrict the use of the onSetRuntimePermissionGrantStateByDeviceAdmin function in AdminRestrictedPermissionsUtils.java to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-189942529
CVE-2023-20914

Affected Products

Android