CVE Published: 11/09/2023 |
CVE Updated: 29/10/2024 |
CVE Year: 2023 Source: google_android |
Vendor: Google |
Product: Android Status : PUBLISHED
CVE-2023-35677 Description
In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not needed for exploitation.