CVE-2023-44126: Call management - Implicit intents disclose telephony data such as phone numbers, call states, contacts
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as call states, durations, called numbers, contacts info, etc.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-44126?
CVE-2023-44126 is a vulnerability in the Call management app patched by LG, which sends LG-owned implicit broadcasts that disclose sensitive data to third-party apps.
What is the severity of CVE-2023-44126?
The severity of CVE-2023-44126 is medium with a severity value of 5.5.
How does CVE-2023-44126 affect Google Android?
CVE-2023-44126 affects Google Android versions 8.0 to 13.0.
How does CVE-2023-44126 affect the LG V60 Thin Q 5G?
The LG V60 Thin Q 5G is not vulnerable to CVE-2023-44126.
How can I fix CVE-2023-44126?
To fix CVE-2023-44126, it is recommended to update the Call management app on your LG device.