CVE-2023-35671

MEDIUM

Google Android - Improper Privilege Management

Title source: rule
STIX 2.1

Description

In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploits (1)

nomisec WRITEUP 73 stars
by MrTiz · poc
https://github.com/MrTiz/CVE-2023-35671

Scores

CVSS v3 5.5
EPSS 0.0019
EPSS Percentile 40.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269
Status published
Products (4)
google/android 11.0
google/android 12.0
google/android 12.1
google/android 13.0
Published Sep 11, 2023
Tracked Since Feb 18, 2026