First published: Fri Mar 24 2023(Updated: )
In ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-253424924References: N/A
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-21046.
The severity of CVE-2023-21046 is medium with a score of 4.4.
This vulnerability can be exploited to perform a local information disclosure with System execution privileges, without requiring user interaction.
The affected software is Google Android.
To fix CVE-2023-21046, it is recommended to apply the patch provided by Google Android. Please refer to the official security bulletin for more details: https://source.android.com/security/bulletin/pixel/2023-03-01