First published: Mon Oct 02 2023(Updated: )
In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | =11.0 | |
Google Android | =12.0 | |
Google Android | =12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-40116.
The title of the vulnerability is 'In onTaskAppeared of PipTaskOrganizer.java there is a possible way to bypass background activity launch restrictions due to a logic error in the code'.
The severity of CVE-2023-40116 is high with a severity value of 7.
The software affected by CVE-2023-40116 is Google Android versions 11.0, 12.0, and 12.1.
The vulnerability can be exploited by bypassing background activity launch restrictions due to a logic error in the code, which could lead to local escalation of privilege without requiring additional execution privileges or user interaction.