CVE-2023-40123: Medium severity Google Android vulnerability
Published Oct 2, 2023
·Updated
In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
5 affected components
Google Android=11.0
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android
Remediation
Patch Available
Event History
Oct 2, 2023
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Oct 27, 2023
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-40123?
CVE-2023-40123 has a moderate severity rating due to its potential for local information disclosure.
2
How do I fix CVE-2023-40123?
To mitigate CVE-2023-40123, update your Android device to the latest security patch provided by Google.
3
Which Android versions are affected by CVE-2023-40123?
CVE-2023-40123 affects Android versions 11.0, 12.0, 12.1, and 13.0.
4
Is user interaction required to exploit CVE-2023-40123?
No, user interaction is not needed to exploit CVE-2023-40123.
5
What kind of impact does CVE-2023-40123 have on my device?
CVE-2023-40123 may allow unauthorized local information disclosure without additional execution privileges.