CVE-2023-21246 Information

Description

In ShortcutInfo of ShortcutInfo.java there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Reference

https://android.googlesource.com/platform/frameworks/base/+/fc1b9998ca8a9fceba47d67fd9ea9b45705b53e0 https://source.android.com/security/bulletin/2023-07-01

Share on: