First published: Mon Oct 02 2023(Updated: )
In onBindingDied of CallRedirectionProcessor.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | =11.0 | |
Google Android | =12.0 | |
Google Android | =12.1 | |
Google Android | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40130 is a vulnerability in the CallRedirectionProcessor.java file of Google Android that could allow a permission bypass and local escalation of privilege.
CVE-2023-40130 has a severity rating of high with a severity value of 7.
The affected software for CVE-2023-40130 is Google Android versions 11.0, 12.0, 12.1, and 13.0.
No, user interaction is not needed for exploitation of CVE-2023-40130.
Yes, you can find more information about CVE-2023-40130 in the references provided: [reference 1](https://android.googlesource.com/platform/packages/services/Telecomm/+/5b335401d1c8de7d1c85f4a0cf353f7f9fc30218), [reference 2](https://source.android.com/docs/security/bulletin/2023-10-01), [reference 3](https://source.android.com/security/bulletin/2023-10-01).