In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a
possible way to access adb before SUW completion due to an insecure default
value. This could lead to local escalation of privilege with no additional
execution privileges needed. User interaction is not needed for
exploitation
References
Configurations
Configuration 1 (hide)
AND |
|
History
13 Feb 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation |
21 Nov 2024, 08:31
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 10.0 |
References | () http://packetstormsecurity.com/files/176446/Android-DeviceVersionFragment.java-Privilege-Escalation.html - | |
References | () https://source.android.com/docs/security/bulletin/pixel-watch/2023/2023-12-01 - Vendor Advisory |
10 Jan 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
09 Jan 2024, 17:30
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
First Time |
Google pixel Watch
Google pixel Watch Firmware |
|
CPE | cpe:2.3:h:google:pixel_watch:11:*:*:*:*:*:*:* cpe:2.3:o:google:pixel_watch_firmware:-:*:*:*:*:*:*:* |
|
References | () https://source.android.com/docs/security/bulletin/pixel-watch/2023/2023-12-01 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
03 Jan 2024, 13:48
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
02 Jan 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-02 23:15
Updated : 2025-02-13 18:15
NVD link : CVE-2023-48418
Mitre link : CVE-2023-48418
CVE.ORG link : CVE-2023-48418
JSON object : View
Products Affected
- pixel_watch
- pixel_watch_firmware
CWE