CVE-2023-40127: Low severity Google Android vulnerability
In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-40127?
CVE-2023-40127 is a vulnerability that allows for a possible way to access screenshots due to a confused deputy, leading to local information disclosure on Google Android devices.
How severe is CVE-2023-40127?
CVE-2023-40127 has a severity rating of high (3.3).
How can CVE-2023-40127 be exploited?
CVE-2023-40127 can be exploited without user interaction by taking advantage of the confused deputy issue.
Which versions of Google Android are affected by CVE-2023-40127?
CVE-2023-40127 affects Google Android versions 11.0, 12.0, 12.1, and 13.0.
Where can I find more information about CVE-2023-40127?
You can find more information about CVE-2023-40127 at the following references: [reference_1](https://android.googlesource.com/platform/packages/providers/MediaProvider/+/747431250612507e8289ae8eb1a56303e79ab678), [reference_2](https://source.android.com/docs/security/bulletin/2023-10-01), [reference_3](https://source.android.com/security/bulletin/2023-10-01).