Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-48418

Description

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a    possible way to access adb before SUW completion due to an insecure default    value. This could lead to local escalation of privilege with no additional    execution privileges needed. User interaction is not needed for    exploitation

POC

Reference

- http://packetstormsecurity.com/files/176446/Android-DeviceVersionFragment.java-Privilege-Escalation.html

Github

- https://github.com/fkie-cad/nvd-json-data-feeds