Local Escalation of Privilege in Android Telecommunication Services by Google
CVE-2023-40130
7.8HIGH
Key Information:
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2023-40130?
A logic error in the CallRedirectionProcessor.java file within Google's Android Telecommunication Services allows a possible permission bypass. This vulnerability can facilitate local escalation of privilege, enabling unauthorized background activities without additional execution privileges. Notably, exploitation does not require user interaction, posing significant security concerns for Android users.
Affected Version(s)
Android 13
Android 12L
Android 12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.