CVE-2023-44128

MEDIUM

Android 4.0-12.0 - Arbitrary File Deletion via LGInstallService AIDL Interface Race Condition

Title source: llm
STIX 2.1

Description

he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete file method. An attacker can control conditions so this security check is never performed and an attacker-controlled file is deleted.

References (1)

Core 1
Core References

Scores

CVSS v3 5.0
EPSS 0.0007
EPSS Percentile 0.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (1)
google/android 4.0 - 13.0
Published Sep 27, 2023
Tracked Since Feb 18, 2026