CVE-2023-42749: Medium severity android vulnerability
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42749?
CVE-2023-42749 is a vulnerability in the enginnermode service in Google Android and Unisoc devices that allows an attacker to write permission usage records of an app without the proper permission check, leading to potential local information disclosure.
Which software versions are affected by CVE-2023-42749?
CVE-2023-42749 affects Google Android versions 11.0, 12.0, and 13.0, as well as Unisoc devices running certain vulnerable chipsets.
What is the severity rating of CVE-2023-42749?
CVE-2023-42749 has a severity rating of 5.5 (medium).
How can an attacker exploit CVE-2023-42749?
An attacker can exploit CVE-2023-42749 by taking advantage of the missing permission check in the enginnermode service to write permission usage records of an app, potentially leading to local information disclosure.
Is there a fix for CVE-2023-42749?
At this time, there is no available fix for CVE-2023-42749. It is recommended to follow the official announcements and updates from Google and Unisoc for any patches or mitigation measures.