Privilege Escalation Vulnerability in Yandex Navigator for Android
CVE-2023-29749

7.8HIGH

Key Information:

Vendor

Yandex

Status
Vendor
CVE Published:
9 June 2023

What is CVE-2023-29749?

An escalation of privilege vulnerability exists in Yandex Navigator for Android, specifically in version 6.60. This flaw allows unauthorized applications to exploit the SharedPreference files, potentially leading to unauthorized access and manipulation of sensitive data within the app. Such vulnerabilities can compromise user security and privacy, emphasizing the need for timely updates and security measures.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.