In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a
possible way to access adb before SUW completion due to an insecure default
value. This could lead to local escalation of privilege with no additional
execution privileges needed. User interaction is not needed for
exploitation
References
Configurations
Configuration 1 (hide)
AND |
|
History
13 Feb 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation |
Information
Published : 2024-01-02 23:15
Updated : 2025-02-13 18:15
NVD link : CVE-2023-48418
Mitre link : CVE-2023-48418
CVE.ORG link : CVE-2023-48418
JSON object : View
Products Affected
- pixel_watch_firmware
- pixel_watch
CWE