First published: Mon Feb 06 2023(Updated: )
In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-248251018
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =10.0 | |
Android | =11.0 | |
Android | =12.0 | |
Android | =12.1 | |
Android | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-20932 is classified as moderate due to its potential for local information disclosure.
To fix CVE-2023-20932, ensure that your Android device is updated to the latest security patch provided by Google.
CVE-2023-20932 affects Android versions 10.0, 11.0, 12.0, 12.1, and 13.0.
No, user interaction is not needed for exploiting CVE-2023-20932.
CVE-2023-20932 can lead to the disclosure of contacts belonging to other users.