CVE-2023-48418

CRITICAL

Google Pixel Watch Firmware - Local Privilege Escalation via Insecure ADB Default Value

Title source: llm
STIX 2.1

Description

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no additional     execution privileges needed. User interaction is not needed for     exploitation

Scores

CVSS v3 10.0
EPSS 0.0004
EPSS Percentile 13.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
google/pixel_watch_firmware
Published Jan 02, 2024
Tracked Since Feb 18, 2026