First published: Tue Sep 05 2023(Updated: )
In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =11.0 | |
Google Android | =12.0 | |
Google Android | =12.1 | |
Google Android | =13.0 | |
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35680 is a vulnerability in multiple locations in Google Android that allows an attacker to import contacts belonging to other users, leading to local information disclosure.
The severity of CVE-2023-35680 is high with a severity rating of 5.5.
An attacker can exploit CVE-2023-35680 by taking advantage of a confused deputy situation in multiple locations within the Google Android system to import contacts belonging to other users, resulting in local information disclosure.
Google Android versions 11.0, 12.0, 12.1, and 13.0 are affected by CVE-2023-35680.
No, user interaction is not needed for exploitation of CVE-2023-35680.