CVE-2023-40109
HIGHAndroid - Local Privilege Escalation via UsbConfiguration Parcel Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-40109. PoCs published by uthrasri.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2023-40109, targeting USB accessory and device filtering mechanisms in Android. The code includes classes for USB accessory and device filtering, which can be manipulated to bypass intended restrictions.
Description
In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Exploits (1)
This repository contains functional exploit code for CVE-2023-40109, targeting USB accessory and device filtering mechanisms in Android. The code includes classes for USB accessory and device filtering, which can be manipulated to bypass intended restrictions.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H