CERT-In Vulnerability Note
CIVN-2024-0008
Multiple Vulnerabilities in Android
Original Issue Date:January 11, 2024
Severity Rating: HIGH
Software Affected
- Android Versions 11, 12, 12L, 13, 14
Overview
Multiple vulnerabilities have been reported in Android which could be exploited by an attacker to obtain sensitive information and gain elevated privileges on the targeted system.
Description
These vulnerabilities exist in Android due to flaws in the Framework, System, Google Play system updates, Arm components, Imagination Technologies, MediaTek components, Unisoc components, Qualcomm components and Qualcomm closed-source components.
Successful exploitation of these vulnerabilities could allow the attacker to obtain sensitive information and gain elevated privileges on the targeted system.
Solution
Apply appropriate updates when made available by the respective OEMs:
https://source.android.com/docs/security/bulletin/2024-01-01
Vendor Information
Android
https://source.android.com/docs/security/bulletin/2024-01-01
References
Android
https://source.android.com/docs/security/bulletin/2024-01-01
CVE Name
CVE-2023-21245
CVE-2024-0015
CVE-2024-0018
CVE-2024-0023
CVE-2024-0019
CVE-2024-0021
CVE-2023-40085
CVE-2024-0016
CVE-2024-0017
CVE-2024-0020
CVE-2023-4295
CVE-2023-5427
CVE-2023-21165
CVE-2023-32874
CVE-2023-32872
CVE-2023-48340
CVE-2023-48341
CVE-2023-48342
CVE-2023-48343
CVE-2023-48344
CVE-2023-48348
CVE-2023-48349
CVE-2023-48350
CVE-2023-48351
CVE-2023-48352
CVE-2023-33094
CVE-2023-33108
CVE-2023-33110
CVE-2023-33113
CVE-2023-33114
CVE-2023-33117
CVE-2023-33120
CVE-2023-43514
CVE-2023-21651
CVE-2023-33025
CVE-2023-33036
CVE-2022-33275
CVE-2023-28544
CVE-2023-28548
CVE-2023-28557
CVE-2023-28558
CVE-2023-28559
CVE-2023-28560
CVE-2023-28564
CVE-2023-28565
CVE-2023-28567
CVE-2023-33014
CVE-2023-33030
CVE-2023-33032
CVE-2023-33033
CVE-2023-33037
CVE-2023-33040
CVE-2023-33043
CVE-2023-33044
CVE-2023-33062
CVE-2023-33109
CVE-2023-33112
CVE-2023-43511
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|