CVE-2023-40111
7.8HIGHIn setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privi
Published: 2/15/2024Updated: 3/29/2025
Description
In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
AI AnalysisPowered by AI
Affected Products
googleandroid
14.0
References
- https://android.googlesource.com/platform/frameworks/base/+/55d3d57cbffc838c52d610af14a056dea87b422eMailing ListPatch
- https://source.android.com/security/bulletin/2023-11-01PatchVendor Advisory
- https://android.googlesource.com/platform/frameworks/base/+/55d3d57cbffc838c52d610af14a056dea87b422eMailing ListPatch
- https://source.android.com/security/bulletin/2023-11-01PatchVendor Advisory