In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 29 Apr 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 |

Status: PUBLISHED
Assigner: google_android
Published: 2023-10-27T20:22:56.374Z
Updated: 2025-04-29T19:59:46.887Z
Reserved: 2023-08-09T02:29:31.890Z
Link: CVE-2023-40117

Updated: 2024-08-02T18:24:55.621Z

Status : Modified
Published: 2023-10-27T21:15:08.620
Modified: 2025-04-29T20:15:24.663
Link: CVE-2023-40117

No data.