CVE-2023-44122
CVSS V2 None
CVSS V3 None
Description
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device. They also can return arbitrary data that will be passed to the "onActivityResult()" method. The LockScreenSettings app copies the received file to the "/data/shared/dw/mycategory/wallpaper_01.png" path and then changes the file access mode to world-readable and world-writable.
Overview
- CVE ID
- CVE-2023-44122
- Assigner
- LGE
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-09-27T13:42:52.380Z
- Last Modified Date
- 2023-09-27T13:46:19.798Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://lgsecurity.lge.com/bulletins/mobile#updateDetails | vendor-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-44122 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44122 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 12:24:47 | Added to TrackCVE |