Messaging - Gaining access to arbitrary content providers via QClipIntentReceiverActivity
CVE-2023-44129

3.6LOW

Key Information:

Vendor
CVE Published:
27 September 2023

What is CVE-2023-44129?

The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this functionality by launching this activity and then sending a broadcast with the "com.lge.message.action.QCLIP" action. The attacker can send, e.g., their own data/clipdata and set Intent.FLAG_GRANT_* flags. After the attacker received that intent in the "onActivityResult()" method, they would have access to arbitrary content providers that have the android:grantUriPermissions="true" flag set.

Affected Version(s)

LG V60 Thin Q 5G(LMV600VM) Android 12 <= 13

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.