First published: Mon Mar 06 2023(Updated: )
In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-234442700
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =13.0 | |
Android | ||
=13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20929 has a severity rating of medium due to the potential for local information disclosure.
To fix CVE-2023-20929, update your Android device to version 13.0 or later as it includes the necessary patch.
CVE-2023-20929 affects devices running Android 13.0.
CVE-2023-20929 is an information disclosure vulnerability that allows exposure of nearby Bluetooth MAC addresses.
No, user interaction is not needed for exploitation of CVE-2023-20929.