7.8
CVSSv3

CVE-2023-20947

Published: 24/03/2023 Updated: 29/03/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

In getGroupState of GrantPermissionsViewModel.kt, there is a possible way to keep a one-time permission granted due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237405974

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 12.0

google android 12.1

google android 13.0

Github Repositories

DroidSolver DroidSolver tries to model the android permissions system and help to find vulnerabilities by a Solver approach, using Clingo Usage $ /DroidSolverpy DroidSolver v101 - by @ghizmo Hello DroidSolver! You can choose to use your own script, or find CVEs: 1) Bruteforce my script! 2) Let's see the main script 3) Let's see the CVE-2021-0307 4) Let