CVE-2023-40130

Publication date

2023-10-27 20:22:57

Family

google_android

State

PUBLISHED

Description

In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.