CVE-2023-40130: High severity Google Android vulnerability
In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-40130?
CVE-2023-40130 is a vulnerability in the CallRedirectionProcessor.java file of Google Android that could allow a permission bypass and local escalation of privilege.
How severe is CVE-2023-40130?
CVE-2023-40130 has a severity rating of high with a severity value of 7.
What is the affected software for CVE-2023-40130?
The affected software for CVE-2023-40130 is Google Android versions 11.0, 12.0, 12.1, and 13.0.
Is user interaction required to exploit CVE-2023-40130?
No, user interaction is not needed for exploitation of CVE-2023-40130.
Are there any references for CVE-2023-40130?
Yes, you can find more information about CVE-2023-40130 in the references provided: [reference 1](https://android.googlesource.com/platform/packages/services/Telecomm/+/5b335401d1c8de7d1c85f4a0cf353f7f9fc30218), [reference 2](https://source.android.com/docs/security/bulletin/2023-10-01), [reference 3](https://source.android.com/security/bulletin/2023-10-01).