CVE-2023-44123

MEDIUM

Bluetooth Setting < - Privilege Escalation

Title source: llm
STIX 2.1

Description

The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app. The attacker's app, if it had access to app notifications, could intercept them and redirect them to its activity, before making it grant access permissions to content providers with the `android:grantUriPermissions="true"` flag.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0013
EPSS Percentile 2.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (2)
google/android 12.0
google/android 13.0
Published Sep 27, 2023
Tracked Since Feb 18, 2026