Beveiligingsadvies

CVE-2023-21244

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-10-06 18:48:40
Laatst bijgewerkt 2025-05-01 19:16:57
Toegewezen door google_android
CVSS-score 6.7
Status PUBLISHED

Beschrijving

In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.