CVE-2023-42655: Medium severity android vulnerability
In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42655?
CVE-2023-42655 is a vulnerability in the sim service of certain Android devices, which allows an app to write permission usage records without proper permission checks, potentially leading to privilege escalation.
What is the severity of CVE-2023-42655?
CVE-2023-42655 has a severity level of medium.
Which devices are affected by CVE-2023-42655?
CVE-2023-42655 affects Android version 11.0.
How can I fix CVE-2023-42655?
To fix CVE-2023-42655, users should apply the latest security patches provided by their device manufacturer or update their Android operating system to the latest version.
Where can I find more information about CVE-2023-42655?
More information about CVE-2023-42655 can be found in the official security announcement from Unisoc: https://www.unisoc.com/en_us/secy/announcementDetail/1719615756246777857