CVE-2023-44125: Personalized service - Theft and (over-)write of arbitrary files with system privilege via PendingIntent hijacking
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAGIMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The attacker's app, if it had access to app notifications, could intercept them and redirect them to its activity, before making it grant access permissions to content providers with the android:grantUriPermissions="true" flag.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID CVE-2023-44125?
The vulnerability ID CVE-2023-44125 refers to a vulnerability in the Personalized service ("com.lge.abba") app on LG V60 Thin Q 5G devices running Google Android 12.0 or 13.0.
What is the severity of CVE-2023-44125?
The severity of CVE-2023-44125 is high, with a CVSS score of 7.8.
How does CVE-2023-44125 affect the affected software?
CVE-2023-44125 affects LG V60 Thin Q 5G devices running Google Android 12.0 or 13.0, specifically the Personalized service ("com.lge.abba") app.
What is the impact of CVE-2023-44125?
The impact of CVE-2023-44125 is the theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app.
How can CVE-2023-44125 be fixed?
To fix CVE-2023-44125, users should update their LG V60 Thin Q 5G devices to the latest version of Google Android available and apply any security patches provided by LG.