CVE-2023-40116: High severity Google Android vulnerability
In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-40116.
What is the title of the vulnerability?
The title of the vulnerability is 'In onTaskAppeared of PipTaskOrganizer.java there is a possible way to bypass background activity launch restrictions due to a logic error in the code'.
What is the severity of CVE-2023-40116?
The severity of CVE-2023-40116 is high with a severity value of 7.
Which software is affected by CVE-2023-40116?
The software affected by CVE-2023-40116 is Google Android versions 11.0, 12.0, and 12.1.
How can the vulnerability be exploited?
The vulnerability can be exploited by bypassing background activity launch restrictions due to a logic error in the code, which could lead to local escalation of privilege without requiring additional execution privileges or user interaction.