In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a
possible way to access adb before SUW completion due to an insecure default
value. This could lead to local escalation of privilege with no additional
execution privileges needed. User interaction is not needed for
exploitation
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation | In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation |

Status: PUBLISHED
Assigner: Google_Devices
Published:
Updated: 2025-02-13T17:18:18.657Z
Reserved: 2023-11-16T16:28:09.701Z
Link: CVE-2023-48418

No data.

Status : Modified
Published: 2024-01-02T23:15:11.000
Modified: 2025-02-13T18:15:40.127
Link: CVE-2023-48418

No data.