{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-21272","assignerOrgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","state":"PUBLISHED","assignerShortName":"google_android","dateReserved":"2022-11-03T22:37:50.654Z","datePublished":"2023-08-14T21:01:10.248Z","dateUpdated":"2024-10-09T15:14:06.299Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Android","vendor":"Google","versions":[{"status":"affected","version":"12L"},{"status":"affected","version":"12"},{"status":"affected","version":"11"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>"}],"value":"In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.\n\n"}],"problemTypes":[{"descriptions":[{"description":"Elevation of privilege","lang":"en"}]}],"providerMetadata":{"orgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","shortName":"google_android","dateUpdated":"2023-08-14T21:01:10.248Z"},"references":[{"url":"https://android.googlesource.com/platform/frameworks/base/+/4dea696369a309cf39daa3e94fec7156c290a9c2"},{"url":"https://source.android.com/security/bulletin/2023-08-01"}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T09:28:26.119Z"},"title":"CVE Program Container","references":[{"url":"https://android.googlesource.com/platform/frameworks/base/+/4dea696369a309cf39daa3e94fec7156c290a9c2","tags":["x_transferred"]},{"url":"https://source.android.com/security/bulletin/2023-08-01","tags":["x_transferred"]}]},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-269","lang":"en","description":"CWE-269 Improper Privilege Management"}]}],"affected":[{"vendor":"google","product":"android","cpes":["cpe:2.3:o:google:android:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"11","status":"affected"},{"version":"12","status":"affected"},{"version":"12l","status":"affected"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-10-09T15:08:38.155174Z","id":"CVE-2023-21272","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-10-09T15:14:06.299Z"}}]}}