CVE-2023-21181
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Jun 28, 2023
Updated: Jul 6, 2023
CWE ID 125
Summary
CVE-2023-21181 is a critical vulnerability affecting the Android operating system, specifically in the btm_ble_update_inq_result function of btm_ble_gap.cc. This issue results in a heap buffer overflow, permitting an attacker to perform an out-of-bounds read. The consequences of this vulnerability can lead to local information disclosure, and it does not require user interaction for exploitation. System execution privileges are required to leverage this vulnerability. This issue affects Android-13 and has been assigned the internal ID A-264880969.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Android