CVE-2023-40107 Information
Feb 16, 2024
cve
Description
In ARTPWriter of ARTPWriter.cpp there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Reference
https://android.googlesource.com/platform/frameworks/av/+/acb81624b4f50fed52cb1b3829809ee2f7377093 https://source.android.com/security/bulletin/2023-11-01
Share on: