CVE-2017-13309
Description
In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE
- (none)
Affected
- Google / Android — v=8.1 [affected]
CVSS
- (none)
References
Source
cvelistV5-main/cves/2017/13xxx/CVE-2017-13309.json