CVE-2023-20955
HIGHAndroid - Missing Authorization in AppInfoDashboardFragment
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-20955. PoCs published by Trinadh465.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2023-20955, targeting Android Open Source Project (AOSP) version 10 r33. The exploit appears to involve modifications to the Settings app, potentially leveraging accessibility features or intent handling to achieve privilege escalation or unauthorized actions.
Description
In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and uninstall applications for all users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258653813
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2023-20955, targeting Android Open Source Project (AOSP) version 10 r33. The exploit appears to involve modifications to the Settings app, potentially leveraging accessibility features or intent handling to achieve privilege escalation or unauthorized actions.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H