CVE-2023-21096: Use After Free
Published Apr 3, 2023
·Updated
In OnWakelockReleased of attributionprocessor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-254774758
Affected Software
4 affected components
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android
Remediation
Patch Available
Event History
Apr 3, 2023
CVE Published
via Android·12:00 AM
Apr 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-21096?
CVE-2023-21096 has a high severity rating due to its potential for remote code execution.
2
How can I fix CVE-2023-21096?
To address CVE-2023-21096, update your Android device to the latest available version that includes the security patch.
3
Which Android versions are affected by CVE-2023-21096?
CVE-2023-21096 affects Android versions 12.0, 12.1, and 13.0.
4
Is user interaction required for exploiting CVE-2023-21096?
No, user interaction is not needed for the exploitation of CVE-2023-21096.
5
What type of vulnerability is CVE-2023-21096?
CVE-2023-21096 is classified as a use after free vulnerability.