In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
References
Link | Resource |
---|---|
https://source.android.com/docs/security/bulletin/android-14 | Release Notes Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-10-30 18:15
Updated : 2023-11-07 00:48
NVD link : CVE-2023-21387
Mitre link : CVE-2023-21387
CVE.ORG link : CVE-2023-21387
JSON object : View
Products Affected
- android
CWE
CWE-532
Insertion of Sensitive Information into Log File