← Back

CVE-2023-35676

nvd nist
Published: Sep 11, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected (3)

Products: Google: Android
1 product
Android
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 12.0
Version 12.1
Version 13.0

References (4)

Timeline

No history available yet.