First published: Mon Aug 07 2023(Updated: )
In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =11.0 | |
Google Android | =12.0 | |
Google Android | =12.1 | |
Google Android | =13.0 | |
Google Android | =13.1 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21268 has a moderate severity level due to the potential for local denial of service.
To fix CVE-2023-21268, update your Android device to the latest version provided by Google.
CVE-2023-21268 affects Android versions 11.0, 12.0, 12.1, 13.0, and 13.1.
No, user interaction is not needed for exploitation of CVE-2023-21268.
The primary risk of CVE-2023-21268 is a possible local denial of service affecting SIM recognition.