CVE-2023-44122

CVSS V2 None CVSS V3 None
Description
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device. They also can return arbitrary data that will be passed to the "onActivityResult()" method. The LockScreenSettings app copies the received file to the "/data/shared/dw/mycategory/wallpaper_01.png" path and then changes the file access mode to world-readable and world-writable.
Overview
  • CVE ID
  • CVE-2023-44122
  • Assigner
  • LGE
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-09-27T13:42:52.380Z
  • Last Modified Date
  • 2023-09-27T13:46:19.798Z
References
Reference URL Reference Tags
https://lgsecurity.lge.com/bulletins/mobile#updateDetails vendor-advisory
History
Created Old Value New Value Data Type Notes
2024-06-25 12:24:47 Added to TrackCVE