CERT-In Vulnerability Note
CIVN-2023-0194
Multiple Vulnerabilities in Android OS
Original Issue Date:July 10, 2023
Severity Rating: HIGH
Software Affected
- Android versions 11, 12, 12L, 13
Overview
Multiple Vulnerabilities have been reported in Android OS which could be exploited by an attacker to gain elevated privileges, gain access to sensitive information and cause denial of service (DoS) condition on the targeted system.
Description
These vulnerabilities exist in Android OS due to flaws in Framework, System, Google Play system updates, Kernel, Kernel Components, Arm components, Imagination Technologies, MediaTek components, Qualcomm components and Qualcomm closed-source components.
Successful exploitation of these vulnerabilities could allow an attacker to gain elevated privileges, gain access to sensitive information and cause denial of service condition on the targeted system.
Solution
Apply appropriate updates when made available by the respective OEMs:
https://source.android.com/docs/security/bulletin/2023-07-01
Vendor Information
Android
https://source.android.com/docs/security/bulletin/2023-07-01
References
Android
https://source.android.com/docs/security/bulletin/2023-07-01
CVE Name
CVE-2023-20918
CVE-2023-20942
CVE-2023-21145
CVE-2023-21245
CVE-2023-21251
CVE-2023-21254
CVE-2023-21257
CVE-2023-21262
CVE-2023-21238
CVE-2023-21239
CVE-2023-21249
CVE-2023-21087
CVE-2023-21250
CVE-2023-2136
CVE-2023-21241
CVE-2023-21246
CVE-2023-21247
CVE-2023-21248
CVE-2023-21256
CVE-2023-21261
CVE-2023-20910
CVE-2023-21240
CVE-2023-21243
CVE-2022-42703
CVE-2023-21255
CVE-2023-25012
CVE-2021-29256
CVE-2022-28350
CVE-2023-28147
CVE-2023-26083
CVE-2021-0948
CVE-2023-20754
CVE-2023-20755
CVE-2023-21672
CVE-2023-22386
CVE-2023-22387
CVE-2023-24851
CVE-2023-24854
CVE-2023-28541
CVE-2023-28542
CVE-2023-21629
CVE-2023-21631
CVE-2023-22667
CVE-2023-20910
CVE-2023-21240
CVE-2023-21243
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|