CVE-2023-40111
7.8HIGHIn setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privi
Publicado: 2/15/2024Actualizado: 3/29/2025
Descripción
In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Análisis IAImpulsado por IA
Productos Afectados
googleandroid
14.0
Referencias
- https://android.googlesource.com/platform/frameworks/base/+/55d3d57cbffc838c52d610af14a056dea87b422eMailing ListPatch
- https://source.android.com/security/bulletin/2023-11-01PatchVendor Advisory
- https://android.googlesource.com/platform/frameworks/base/+/55d3d57cbffc838c52d610af14a056dea87b422eMailing ListPatch
- https://source.android.com/security/bulletin/2023-11-01PatchVendor Advisory