CVE-2023-21036

MEDIUM

Android - Info Disclosure

Title source: llm

Description

In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A

Exploits (5)

nomisec WORKING POC 81 stars
by infobyte · poc
https://github.com/infobyte/CVE-2023-21036
nomisec WRITEUP 21 stars
by qixils · poc
https://github.com/qixils/AntiCropalypse
nomisec SCANNER 2 stars
by lordofpipes · poc
https://github.com/lordofpipes/acropadetect
nomisec SCANNER
by PolitoInc · poc
https://github.com/PolitoInc/XWFAcropalypse
nomisec SCANNER
by notaSWE · poc
https://github.com/notaSWE/gocropalypse

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 42.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-703
Status published
Products (1)
google/android
Published Mar 24, 2023
Tracked Since Feb 18, 2026