First published: Mon May 15 2023(Updated: )
In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-256819769
Credit: security@android.com security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =11.0 | |
Google Android | =12.0 | |
Google Android | =12.1 | |
Google Android | =13.0 | |
Google Android | ||
=11.0 | ||
=12.0 | ||
=12.1 | ||
=13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21111 is a vulnerability in the PhoneAccountRegistrar.java file that allows for the prevention of access to emergency services due to improper input validation.
CVE-2023-21111 affects Google Android versions 11.0, 12.0, 12.1, and 13.0.
CVE-2023-21111 has a severity rating of 5.5 (High).
CVE-2023-21111 can be exploited to cause a local denial of service without requiring additional execution privileges.
No, user interaction is not needed for the exploitation of CVE-2023-21111.