CERT-In Vulnerability Note
CIVN-2023-0290
Multiple Vulnerabilities in Android OS
Original Issue Date:October 09, 2023
Severity Rating: CRITICAL
Software Affected
- Android versions 11, 12, 12L, 13
Overview
Multiple Vulnerabilities have been reported in Android OS which could be exploited by an attacker to execute arbitrary code, gain elevated privileges, gain access to sensitive information and cause denial of service (DoS) condition on the targeted system.
Description
These vulnerabilities exist in Android OS due to flaws in Framework, System, Google Play system updates, Arm components, MediaTek components, Unisoc components, Qualcomm components and Qualcomm closed-source components.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, gain elevated privileges, gain access to sensitive information and cause denial of service condition on the targeted system.
Note: CVE-2023-4863 and CVE-2023-4211, may be under active exploitation. Users are advised to apply patches urgently.
Solution
Apply appropriate updates as mentioned by vendor:
https://source.android.com/docs/security/bulletin/2023-10-01
Vendor Information
Android
https://source.android.com/docs/security/bulletin/2023-10-01
References
Android
https://source.android.com/docs/security/bulletin/2023-10-01
CVE Name
CVE-2023-4863
CVE-2023-4211
CVE-2023-21266
CVE-2023-40116
CVE-2023-40120
CVE-2023-40131
CVE-2023-40140
CVE-2023-21291
CVE-2023-40121
CVE-2023-40134
CVE-2023-40136
CVE-2023-40137
CVE-2023-40138
CVE-2023-40139
CVE-2023-40129
CVE-2023-21244
CVE-2023-40117
CVE-2023-40125
CVE-2023-40128
CVE-2023-40130
CVE-2023-40123
CVE-2023-40127
CVE-2023-40133
CVE-2023-40135
CVE-2023-21252
CVE-2023-21253
CVE-2021-44828
CVE-2022-28348
CVE-2023-33200
CVE-2023-34970
CVE-2023-20819
CVE-2023-32819
CVE-2023-32820
CVE-2023-40638
CVE-2023-33029
CVE-2023-33034
CVE-2023-33035
CVE-2023-24855
CVE-2023-28540
CVE-2023-33028
CVE-2023-21673
CVE-2023-22385
CVE-2023-24843
CVE-2023-24844
CVE-2023-24847
CVE-2023-24848
CVE-2023-24849
CVE-2023-24850
CVE-2023-24853
CVE-2023-33026
CVE-2023-33027
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|