CVE-2023-21284
MEDIUMAndroid - Denial of Service via Find My Device Feature Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-21284. PoCs published by Trinadh465.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2023-21284, targeting Android's Autofill framework. The test cases demonstrate how an attacker could manipulate autofill behavior, potentially leading to unauthorized data exposure or UI manipulation.
Description
In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2023-21284, targeting Android's Autofill framework. The test cases demonstrate how an attacker could manipulate autofill behavior, potentially leading to unauthorized data exposure or UI manipulation.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H