CVE-2023-40075

All FrameworksAndroidCWE-OtherCVE-2023-40075

CVE-2023-40075

State: PUBLISHED · Published: 2023-12-04 · Updated: 2024-08-28 · Assigner: google_android
Description
In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/40xxx/CVE-2023-40075.json