Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-40120

In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE
#android#google#auth

)]}’ { "commit": "d26544e5a4fd554b790b4d0c5964d9e95d9e626b", "tree": "f783afd38e1e95b034041806a96ae7f9148b8d68", "parents": [ “88cf23cfe50b80aa9d65cc22946de1765972cb80” ], "author": { "name": "Beth Thibodeau", "email": "[email protected]", "time": “Tue May 30 18:45:47 2023 -0500” }, "committer": { "name": "Android Build Coastguard Worker", "email": "[email protected]", "time": “Thu Aug 10 17:10:15 2023 +0000” }, "message": "Add placeholder when media control title is blank\n\nWhen an app posts a media control with no available title, show a\nplaceholder string with the app name instead\n\nBug: 274775190\nTest: atest MediaDataManagerTest\n(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:a0fda1f36d04331c8d60c5540b09b1a30203581b)\nMerged-In: Ie406c180af48653595e8e222a15b4dda27de2e0e\nChange-Id: Ie406c180af48653595e8e222a15b4dda27de2e0e\n", "tree_diff": [ { "type": "modify", "old_id": "af8d7ed22ed3fe16ab25d720aee3aa9c0f795a91", "old_mode": 33188, "old_path": "packages/SystemUI/res/values/strings.xml", "new_id": "b0fcfcdc2f6b705656dd243fa68b993def4a76ee", "new_mode": 33188, "new_path": “packages/SystemUI/res/values/strings.xml” }, { "type": "modify", "old_id": "6a69d427929e1f2f439eebe7bd3199a58d29a519", "old_mode": 33188, "old_path": "packages/SystemUI/src/com/android/systemui/media/MediaDataManager.kt", "new_id": "4c2336eeb22c09f282069945a659cb458aecfee0", "new_mode": 33188, "new_path": “packages/SystemUI/src/com/android/systemui/media/MediaDataManager.kt” }, { "type": "modify", "old_id": "1cce7cfb5b8afcc06fb87a71601185c5cfd23d38", "old_mode": 33188, "old_path": "packages/SystemUI/tests/src/com/android/systemui/media/MediaDataManagerTest.kt", "new_id": "52266f983fddc351aead9a906c42034e63d9ee55", "new_mode": 33188, "new_path": “packages/SystemUI/tests/src/com/android/systemui/media/MediaDataManagerTest.kt” } ] }

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907