CVE-2023-35669

All FrameworksAndroidCWE-OtherCVE-2023-35669

CVE-2023-35669

State: PUBLISHED · Published: 2023-09-11 · Updated: 2024-09-26 · Assigner: google_android
Description
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/35xxx/CVE-2023-35669.json