In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: google_android

Published: 2023-09-11T20:09:52.808Z

Updated: 2023-09-11T20:16:40.959Z

Reserved: 2023-06-15T02:50:29.819Z


Link: CVE-2023-35669

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-09-11T21:15:41.960

Modified: 2023-09-14T01:44:54.843


Link: CVE-2023-35669

JSON object: View

cve-icon Redhat Information

No data.

CWE