In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-216117246
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: google_android
Published: 2023-03-24T00:00:00.000Z
Updated: 2025-02-25T16:19:57.806Z
Reserved: 2022-11-03T00:00:00.000Z
Link: CVE-2023-20976

Updated: 2024-08-02T09:21:33.593Z

Status : Modified
Published: 2023-03-24T20:15:11.373
Modified: 2025-02-25T17:15:13.207
Link: CVE-2023-20976

No data.