CVE Database
/

CVE-2023-21270

Back to search

CVE-2023-21270

Published: Nov 19, 2024

Modified: Nov 20, 2024

PUBLISHED

Description

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

VendorProductVersions

Google

Andrioid

affected
sc-dev
affected
sc-v2-dev
affected
tm-dev

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now