CVE-2023-21246 Information
Jul 14, 2023
cve
Description
In ShortcutInfo of ShortcutInfo.java there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Reference
https://android.googlesource.com/platform/frameworks/base/+/fc1b9998ca8a9fceba47d67fd9ea9b45705b53e0 https://source.android.com/security/bulletin/2023-07-01
Share on: