CVE-2023-44128: LGInstallService - Deletion of arbitrary files with system privilege
he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete file method. An attacker can control conditions so this security check is never performed and an attacker-controlled file is deleted.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-44128?
CVE-2023-44128 is a vulnerability that allows an attacker to delete arbitrary files in the LGInstallService app.
What software is affected by CVE-2023-44128?
Google Android versions 4.0 to 13.0 and LG V60 Thin Q 5g are affected by CVE-2023-44128.
What is the severity of CVE-2023-44128?
CVE-2023-44128 has a severity rating of medium (3.6).
How can an attacker exploit CVE-2023-44128?
An attacker can exploit CVE-2023-44128 by leveraging the exported "com.lge.lginstallservies.InstallService" service in the LGInstallService app to delete arbitrary files.
Is there a fix available for CVE-2023-44128?
It is recommended to update to the latest version of Google Android or LG V60 Thin Q 5g to mitigate CVE-2023-44128.