ASB-A-269014004
Dashboard / Vulnerabilities / ASB-A-269014004
Summary:
Details: In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References: https://source.android.com/security/bulletin/2023-05-01, https://android.googlesource.com/platform/frameworks/native/+/481ec5ccde7a7c10abf1111931a776d8d1644fcb, https://android.googlesource.com/platform/frameworks/native/+/74b71c0674a74d0b91353760070cca4af57937a6, https://android.googlesource.com/platform/frameworks/native/+/21e0d9bfb8893ea3cc9c3462bc4cf73d095b757a
Affected packages
Package
Name: platform/frameworks/native
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
