CVE-2023-21026 Information
Mar 25, 2023
cve
Description
In updateInputChannel of WindowManagerService.java there is a possible way to set a touchable region beyond its own SurfaceControl due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-254681548
Reference
https://source.android.com/security/bulletin/pixel/2023-03-01
Share on: