CVE-2023-48403

HIGH

Android - Out-of-bounds Write in sms_DecodeCodedTpMsg

Title source: llm
STIX 2.1

Description

In sms_DecodeCodedTpMsg of sms_PduCodec.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure if the attacker is able to observe the behavior of the subsequent switch conditional with no additional execution privileges needed. User interaction is not needed for exploitation.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0022
EPSS Percentile 44.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-787
Status published
Products (1)
google/android
Published Dec 08, 2023
Tracked Since Feb 18, 2026