First published: Mon Dec 04 2023(Updated: )
In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
=11.0 | ||
=12.0 | ||
=12.1 | ||
=13.0 | ||
=14.0 |
https://android.googlesource.com/platform/frameworks/av/+/58fd993a89a3a22fa5a4a1a4548125c6783ec80c
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-40077 is a vulnerability in multiple functions of MetaDataBase.cpp in Google Android that allows for a possible use-after-free write due to a race condition, potentially leading to remote escalation of privilege.
CVE-2023-40077 has a severity rating of critical with a score of 9.
CVE-2023-40077 could lead to remote escalation of privilege in Google Android without requiring additional execution privileges or user interaction.
CVE-2023-40077 can be exploited by leveraging the use-after-free write vulnerability caused by the race condition in multiple functions of MetaDataBase.cpp.
Yes, a fix for CVE-2023-40077 is available. Please refer to the official Android Security Bulletin for more information.