First published: Wed Sep 27 2023(Updated: )
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The attacker's app, if it had access to app notifications, could intercept them and redirect them to its activity, before making it grant access permissions to content providers with the `android:grantUriPermissions="true"` flag.
Credit: product.security@lge.com product.security@lge.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =12.0 | |
Google Android | =13.0 | |
Lg V60 Thin Q 5g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID CVE-2023-44125 refers to a vulnerability in the Personalized service ("com.lge.abba") app on LG V60 Thin Q 5G devices running Google Android 12.0 or 13.0.
The severity of CVE-2023-44125 is high, with a CVSS score of 7.8.
CVE-2023-44125 affects LG V60 Thin Q 5G devices running Google Android 12.0 or 13.0, specifically the Personalized service ("com.lge.abba") app.
The impact of CVE-2023-44125 is the theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app.
To fix CVE-2023-44125, users should update their LG V60 Thin Q 5G devices to the latest version of Google Android available and apply any security patches provided by LG.