In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-234442700
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://source.android.com/security/bulletin/2023-03-01 |
![]() ![]() |
History
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: google_android
Published: 2023-03-24T00:00:00.000Z
Updated: 2025-02-28T20:34:22.021Z
Reserved: 2022-11-03T00:00:00.000Z
Link: CVE-2023-20929

Updated: 2024-08-02T09:21:33.528Z

Status : Modified
Published: 2023-03-24T20:15:09.303
Modified: 2025-02-28T21:15:19.983
Link: CVE-2023-20929

No data.