In onActivityResult of... CVE-2023-20912

- AV AC AU C I A
发布: 2023-01-26
修订: 2023-02-02

In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246301995

0%
暂无可用Exp或PoC
当前有1条受影响产品信息