CVE-2023-21268

All FrameworksAndroidCWE-OtherCVE-2023-21268

CVE-2023-21268

State: PUBLISHED · Published: 2023-08-14 · Updated: 2024-10-09 · Assigner: google_android
Description
In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/21xxx/CVE-2023-21268.json