CVE-2023-21270

HIGH

Android - Local Privilege Escalation via Incorrect Permission Flags

Title source: llm
STIX 2.1

Description

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 8.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276 CWE-863
Status published
Products (3)
google/android 12.0
google/android 12.1
google/android 13.0
Published Nov 19, 2024
Tracked Since Feb 18, 2026