In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-234442700
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/2023-03-01 | Patch Vendor Advisory |
https://source.android.com/security/bulletin/2023-03-01 | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-03-24 20:15
Updated : 2025-02-28 21:15
NVD link : CVE-2023-20929
Mitre link : CVE-2023-20929
CVE.ORG link : CVE-2023-20929
JSON object : View
Products Affected
- android
CWE