Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-20904. PoCs published by FishMan132.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2023-20904, demonstrating how an attacker can manipulate Android Intents with selectors to redirect to malicious activities. The vulnerable app parses URIs without clearing the selector, allowing intent redirection.
Description
In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-246300272
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2023-20904, demonstrating how an attacker can manipulate Android Intents with selectors to redirect to malicious activities. The vulnerable app parses URIs without clearing the selector, allowing intent redirection.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H